MALICIOUS — 8eaa4825422bd.pdf
MALICIOUS — 8eaa4825422bd.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
66b17035f8e0ae755584419c93d14a37803719a3a2ab24e3f4343a815f7bef34 - SHA-1:
3d782aec7ed0a3a351f01ce4d29216aa96a4577d - MD5:
2206e08bc495070eebdadbc7e6071a42 - ssdeep:
1536:qGFlYT2zzIs/8vywAwInVEtq2GyoO+X394Q57UAWHqSiraAVqWzdInxwmTOwGOeL:TFlYTEDkvyvVVEpZ+X3h7UDiraAV1dSa - TLSH:
T10D39D1F3109BFC1D6ACE9F47E9991969348797C8712697B010D82BACC0BC67D7E60A40 - Submitted as: 8eaa4825422bd.pdf
- File type: pdf · Size: 91305 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/gapit-galijawijekinik-kedafel.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=%D8%AF%D8%A7%D9%86%D9%84%D9%88%D8%AF%20%D8%B1%D9%85%D8%A7%D9%86%20%D8%B9%D8%A7%D8%B4%D9%82%D8%A7%D9%86%D9%87%20%D8%A7%DB%8C%D8%B1%D8%A7%D9%86%DB%8C%20%D8%AC%D8%AF%DB%8C%D8%AF%20pdf, https://uploads.strikinglycdn.com/files/5a4c95c4-c1a4-4ee3-92a4-88e620ae92d5/48571801990.pdf, https://uploads.strikinglycdn.com/files/51a0003a-d417-495c-99a6-344613a7ecbe/73565027551.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=%D8%AF%D8%A7%D9%86%D9%84%D9%88%D8%AF%20%D8%B1%D9%85%D8%A7%D9%86%20%D8%B9%D8%A7%D8%B4%D9%82%D8%A7%D9%86%D9%87%20%D8%A7%DB%8C%D8%B1%D8%A7%D9%86%DB%8C%20%D8%AC%D8%AF%DB%8C%D8%AF%20pdf
- https://uploads.strikinglycdn.com/files/5a4c95c4-c1a4-4ee3-92a4-88e620ae92d5/48571801990.pdf
- https://uploads.strikinglycdn.com/files/51a0003a-d417-495c-99a6-344613a7ecbe/73565027551.pdf
- https://uploads.strikinglycdn.com/files/008b424b-bebd-4573-94aa-bdf07a272f83/7301228989.pdf
- https://cdn.shopify.com/s/files/1/0435/6639/9647/files/19957184235.pdf
- https://cdn.shopify.com/s/files/1/0433/9816/8743/files/root_chakra_sleep_guided_meditation.pdf
- https://cdn.shopify.com/s/files/1/0484/7727/4274/files/12021535827.pdf
- https://cdn.shopify.com/s/files/1/0482/1165/6861/files/27909014972.pdf
- https://cdn.shopify.com/s/files/1/0430/8870/7738/files/jamavatadelarilo.pdf
- https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/gapit-galijawijekinik-kedafel.pdf
- https://wavuvavezexa.weebly.com/uploads/1/3/0/7/130775629/5474497b3f4.pdf
- https://sijevunima.weebly.com/uploads/1/3/1/8/131859613/ad122d29df.pdf
- https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/pujosadugebafimeduko.pdf
- https://s3.amazonaws.com/pazifetanegapu/1_goal_free_education_for_all.pdf
- https://s3.amazonaws.com/wefadep/bazav.pdf
- https://s3.amazonaws.com/pasawexawinogad/actin_binding_proteins.pdf
- https://s3.amazonaws.com/wexukufedepim/basics_of_engineering_drawing.pdf
- https://rabifupokuwu.weebly.com/uploads/1/3/1/1/131164250/mosizugetexuniz.pdf
- https://nipufijupetobug.weebly.com/uploads/1/3/1/4/131482996/kawudadupug.pdf
- https://s3.amazonaws.com/nezanurugega/texutalevakaviwuvira.pdf
- https://s3.amazonaws.com/henghuili-files/joxugozurinotisupoxaro.pdf
- https://s3.amazonaws.com/mutirexa/6786420510.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- pigogokeda.weebly.com
- wavuvavezexa.weebly.com
- sijevunima.weebly.com
- tivakoxidedopa.weebly.com
- s3.amazonaws.com
- rabifupokuwu.weebly.com
- nipufijupetobug.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report