MALICIOUS — 8020923.pdf
MALICIOUS — 8020923.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6a68e08412e6b54270ca113ed3870bc70284eb2f3f048666c5ccf1c220b929c4 - SHA-1:
f92f39d18dc3019388eb76e940e0f62398818910 - MD5:
814ecbd5d2c8d8c630e8e9923d085765 - ssdeep:
768:ngGzpDbphRWppUV1HV04HduwvBJMm3E5YV1bOlXk03iqWGeNdJsAIi4qVNW:gGFXpwYPbF0yqWliLi4qVNW - TLSH:
T148318EF7A097ED4D7A8F6F13ADEA1059A54AC388A02397A0804C372CD4BC6BD6F01D55 - Submitted as: 8020923.pdf
- File type: pdf · Size: 42542 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://gonoloxezejuje.weebly.com/uploads/1/3/1/4/131410007/7035760.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=mileage%20log%20book%20for%20irs, https://kesevaze.weebly.com/uploads/1/3/1/3/131383297/bf7d2948e6.pdf, https://netaluzubik.weebly.com/uploads/1/3/0/8/130813777/mogimajavurag_goviwedoko.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=mileage%20log%20book%20for%20irs
- https://kesevaze.weebly.com/uploads/1/3/1/3/131383297/bf7d2948e6.pdf
- https://netaluzubik.weebly.com/uploads/1/3/0/8/130813777/mogimajavurag_goviwedoko.pdf
- https://sakuvida.weebly.com/uploads/1/3/0/7/130775714/fapobojeje-zalidusak.pdf
- https://gonoloxezejuje.weebly.com/uploads/1/3/1/4/131410007/7035760.pdf
- https://cdn.shopify.com/s/files/1/0435/0646/6975/files/42829520474.pdf
- https://cdn.shopify.com/s/files/1/0483/5940/7765/files/life_after_apk_obb_english.pdf
- https://cdn.shopify.com/s/files/1/0433/8476/6620/files/79421935249.pdf
- https://cdn.shopify.com/s/files/1/0497/5978/1023/files/chopin_piano_nocturne.pdf
- https://cdn.shopify.com/s/files/1/0493/1167/8623/files/lefelu.pdf
- https://cdn.shopify.com/s/files/1/0438/7612/2779/files/52002452175.pdf
- https://cdn-cms.f-static.net/uploads/4365626/normal_5f87476317759.pdf
- https://cdn-cms.f-static.net/uploads/4365662/normal_5f8d13f5a2f8a.pdf
- https://cdn-cms.f-static.net/uploads/4378405/normal_5f8a5a2d9fd38.pdf
- https://cdn-cms.f-static.net/uploads/4385434/normal_5f8d254b40d80.pdf
- https://cdn-cms.f-static.net/uploads/4366305/normal_5f8ccc801ac47.pdf
- https://cdn-cms.f-static.net/uploads/4379611/normal_5f8c749040b4d.pdf
- https://cdn-cms.f-static.net/uploads/4383132/normal_5f8be275600a7.pdf
- https://cdn-cms.f-static.net/uploads/4374853/normal_5f89aa7f045f4.pdf
- https://cdn-cms.f-static.net/uploads/4387410/normal_5f8cf6e9d7519.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- kesevaze.weebly.com
- netaluzubik.weebly.com
- sakuvida.weebly.com
- gonoloxezejuje.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report