MALICIOUS — d63b4.pdf
MALICIOUS — d63b4.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6785774d21df941a93e69ac4b6bbe528f79c4f068e0f7931b6dc4916c0154a01 - SHA-1:
2fc607534ec180656fe8fe12b36de084885a4567 - MD5:
c49823a231cc57e80881715cbf7406a3 - ssdeep:
1536:7GFzprGtu0l8B5zSeYt3AfE1vdhL8YVn9c1h7MQzx6yh:aFzp6tlkZSeM37x7L8On+v7P - TLSH:
T12D34BFF350A7EC4C7B8AAB036DF6145D218AD788A137D76448C8372DD47C9DEAE109A0 - Submitted as: d63b4.pdf
- File type: pdf · Size: 52691 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/0da0dd5f-f503-4571-a04f-cfbfb2989846/zonanumukuvafalebefasu.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=oracle%20enterprise%20manager%2012c%20installation, https://uploads.strikinglycdn.com/files/53f1268a-c298-4439-bd10-347bf0fdf5c3/56773883676.pdf, https://uploads.strikinglycdn.com/files/80b33419-a780-4cf5-b16e-0dc466ed4c1f/63917284207.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=oracle%20enterprise%20manager%2012c%20installation
- https://uploads.strikinglycdn.com/files/53f1268a-c298-4439-bd10-347bf0fdf5c3/56773883676.pdf
- https://uploads.strikinglycdn.com/files/80b33419-a780-4cf5-b16e-0dc466ed4c1f/63917284207.pdf
- https://uploads.strikinglycdn.com/files/9c58e31c-5436-4a48-979c-9c8a4545fe2c/31203573587.pdf
- https://uploads.strikinglycdn.com/files/0da0dd5f-f503-4571-a04f-cfbfb2989846/zonanumukuvafalebefasu.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/3297565.pdf
- https://goduvozimaku.weebly.com/uploads/1/3/1/3/131380582/2652839.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/mukobuf.pdf
- https://uploads.strikinglycdn.com/files/49ddcc19-a2b1-43ab-971b-37f13dc5c1fe/90278875353.pdf
- https://uploads.strikinglycdn.com/files/f652c993-6949-400e-aee0-94732e51636b/vukov.pdf
- https://uploads.strikinglycdn.com/files/56f20854-5bca-4003-aa57-23217e370ea1/sepupe.pdf
- https://uploads.strikinglycdn.com/files/5b3a0d7a-f03d-489c-ab3d-e6d6787350a7/fojizeboval.pdf
- https://cdn.shopify.com/s/files/1/0479/6327/5431/files/pananozasowixatadoxubovon.pdf
- https://cdn.shopify.com/s/files/1/0477/5700/0860/files/96110039206.pdf
- https://cdn.shopify.com/s/files/1/0502/7994/0296/files/78050615580.pdf
- https://cdn.shopify.com/s/files/1/0488/5368/0284/files/muruxow.pdf
- https://cdn.shopify.com/s/files/1/0460/2019/8559/files/na_just_for_today_app_free.pdf
- https://cdn.shopify.com/s/files/1/0495/1428/3176/files/notuxenudikabox.pdf
- https://cdn.shopify.com/s/files/1/0435/5050/7167/files/sony_bookshelf_speakers_bluetooth.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- xojerajap.weebly.com
- goduvozimaku.weebly.com
- zoxuzuxebexot.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report