MALICIOUS — 4971694.pdf
MALICIOUS — 4971694.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6c80273e4720383ef3af7b17d158d3003a2881a98414cce0d667f508228c09b0 - SHA-1:
4bed3535dfc7139555298f1d6c5e15bcbc462dda - MD5:
bcb322dd7cf8e24e8e977f41e865274f - ssdeep:
1536:PGFYec6NbVR/nd/xW2ZkYQuO2RqrXEtEMZj:+FYD8bzn5eYK2RkXEtF - TLSH:
T13F34ADF3618BDD4C7A8BAB839EE700985046D788623A83A0419C776CC57C2EC7F51A65 - Submitted as: 4971694.pdf
- File type: pdf · Size: 57510 bytes
- Verdict: malicious (75/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://kokubexajaluk.weebly.com/uploads/1/3/2/6/132681668/3745293.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=virus%20de%20distemper%20canino%20pdf, https://nitetezelimon.weebly.com/uploads/1/3/1/4/131438651/kegusadatewunar_banifiwi_dovisupibezi_jegurip.pdf, https://vonegulozezuxe.weebly.com/uploads/1/3/4/3/134371031/6556063.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=virus%20de%20distemper%20canino%20pdf
- https://nitetezelimon.weebly.com/uploads/1/3/1/4/131438651/kegusadatewunar_banifiwi_dovisupibezi_jegurip.pdf
- https://vonegulozezuxe.weebly.com/uploads/1/3/4/3/134371031/6556063.pdf
- https://mixorone.weebly.com/uploads/1/3/1/4/131438240/adf0df6.pdf
- https://gedejapel.weebly.com/uploads/1/3/4/3/134314995/1535928.pdf
- https://s3.amazonaws.com/fasanag/present_tenses_exercises_upper_intermediate.pdf
- https://s3.amazonaws.com/xanebavifamopez/tikiduwogopejewaxujobisu.pdf
- https://s3.amazonaws.com/zuxadol/introduction_to_business_administration_books.pdf
- https://uploads.strikinglycdn.com/files/e4555d83-864f-4eea-8141-2e3fdb84cebc/rupewanopuneboxawuriko.pdf
- https://uploads.strikinglycdn.com/files/80fbb995-ec6d-4fb6-bb12-a856eab51751/63270944051.pdf
- https://cdn.shopify.com/s/files/1/0438/1966/3522/files/nomenclature_des_alcanes_ramifis_exercice.pdf
- https://cdn.shopify.com/s/files/1/0486/4458/7688/files/air_display_apk_download.pdf
- https://kokubexajaluk.weebly.com/uploads/1/3/2/6/132681668/3745293.pdf
- https://kokubexajaluk.weebly.com/uploads/1/3/2/6/132681668/2795039.pdf
- https://uploads.strikinglycdn.com/files/9d4d47a9-d0c3-4205-825e-d9656d5f04b8/retivagomusakefom.pdf
- https://uploads.strikinglycdn.com/files/a1bf1bcb-1500-474a-b8e4-329a28548a52/51491336336.pdf
- https://uploads.strikinglycdn.com/files/093f1201-f58d-467e-ab5d-056c5afb53be/sodosuxomilatijepovuwu.pdf
- https://uploads.strikinglycdn.com/files/6da67c50-7fc5-4b05-88be-3cc597f427a2/24744441957.pdf
- https://uploads.strikinglycdn.com/files/0fbd6880-d8a5-4db6-a952-20c6257ef33b/94998374456.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- nitetezelimon.weebly.com
- vonegulozezuxe.weebly.com
- mixorone.weebly.com
- gedejapel.weebly.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- kokubexajaluk.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report