MALICIOUS — 4775936.pdf
MALICIOUS — 4775936.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
66b56627cc78b1ab810b45bdb5e6d3e3467435d8e469362ee1a39e099043b3d8 - SHA-1:
66628e656f66da42540997665de0c5806abc0f1b - MD5:
facb036b7ccc7225f0fb74b66ded3f38 - ssdeep:
768:kgGzpDXeip9lTev9LmM/YuU45/ITsHwhFYltRC+s20s2olVqrkKGDUIADkSmt:RGF7eVMTsHwYNs20s2kvKGDUIAYSmt - TLSH:
T12634AFF340A7ECCC77868B13ADAB11AA6589D748A132ABA054CC777CD17C1BE7E14910 - Submitted as: 4775936.pdf
- File type: pdf · Size: 55767 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://tavumake.weebly.com/uploads/1/3/2/7/132740551/21083.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=nba%202k12%20press%20conference%20answers, https://cdn-cms.f-static.net/uploads/4369496/normal_5f8ee289269b3.pdf, https://cdn-cms.f-static.net/uploads/4379483/normal_5f8d944781d30.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=nba%202k12%20press%20conference%20answers
- https://cdn-cms.f-static.net/uploads/4369496/normal_5f8ee289269b3.pdf
- https://cdn-cms.f-static.net/uploads/4379483/normal_5f8d944781d30.pdf
- https://cdn-cms.f-static.net/uploads/4368486/normal_5f889e8173433.pdf
- https://cdn-cms.f-static.net/uploads/4368962/normal_5f87d61e30062.pdf
- https://cdn.shopify.com/s/files/1/0484/8284/4834/files/toms_diner_song_meaning.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/21083.pdf
- https://tenikekiso.weebly.com/uploads/1/3/0/7/130775729/e20be82686.pdf
- https://xebikazogede.weebly.com/uploads/1/3/2/7/132740990/3251463.pdf
- https://varipejat.weebly.com/uploads/1/3/0/7/130739080/eca4ccfadd4e11a.pdf
- https://vodipewelo.weebly.com/uploads/1/3/1/6/131637384/gaxawavoziduvit.pdf
- https://cdn.shopify.com/s/files/1/0462/3876/1109/files/kadonowetibet.pdf
- https://cdn.shopify.com/s/files/1/0431/3609/0269/files/medium_clue_scroll_maps_rs3.pdf
- https://cdn.shopify.com/s/files/1/0495/7175/8232/files/37189800907.pdf
- https://cdn.shopify.com/s/files/1/0497/9222/1346/files/92222677739.pdf
- https://cdn.shopify.com/s/files/1/0486/1417/8976/files/11929764986.pdf
- https://cdn.shopify.com/s/files/1/0483/7297/3728/files/26400199565.pdf
- https://cdn.shopify.com/s/files/1/0485/7797/0341/files/terraria_calamity_mod_legendary_weapons.pdf
- https://s3.amazonaws.com/xanebavifamopez/53507376847.pdf
- https://s3.amazonaws.com/subud/pulimufexisimewajoba.pdf
- https://s3.amazonaws.com/wonoti/ginisiguteput.pdf
- https://s3.amazonaws.com/pazifetanegapu/92181930445.pdf
- https://s3.amazonaws.com/xanebavifamopez/darklight_memento_mori.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- tavumake.weebly.com
- tenikekiso.weebly.com
- xebikazogede.weebly.com
- varipejat.weebly.com
- vodipewelo.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report