MALICIOUS — 93796204588.pdf
MALICIOUS — 93796204588.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6fa9a1a4aeec3c06709c8a87d52ecf9f32e743daa5cc7d7166964ca87d82c62a - SHA-1:
b21f0e3e2f3301636234a7d35d0d096d2899e7c8 - MD5:
9608fa4ff606f27416e92c10b91d5401 - ssdeep:
768:JgGzpDIpl8MrFeppNxY+p751UTCOhgsLeXrwbsMJTQxP:qGFcpeppLY+p751UTnLC7211QxP - TLSH:
T1BE319DF314A7ED8C6A87AB0399AB1598548AC38D6237D7A04588337DC4FC6BC6F50970 - Submitted as: 93796204588.pdf
- File type: pdf · Size: 42441 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/7775416.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=amazon+app+store+free+apk, https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/zebapesuluboxaj.pdf, https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/7775416.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=amazon+app+store+free+apk
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/zebapesuluboxaj.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/7775416.pdf
- https://ruwopevod.weebly.com/uploads/1/3/1/3/131397973/porenakis.pdf
- https://uploads.strikinglycdn.com/files/4aefab6f-03d9-4bde-bbfe-26509ad8b821/xujowisa.pdf
- https://uploads.strikinglycdn.com/files/953dc0e4-ba0b-4eb3-8193-05248c228832/80105796722.pdf
- https://uploads.strikinglycdn.com/files/aee59cf0-77fd-4890-8085-136309273e3b/43599289748.pdf
- https://uploads.strikinglycdn.com/files/db915c87-c07b-4efd-acae-9b58139c1c3f/rasat.pdf
- https://uploads.strikinglycdn.com/files/a85b22bb-207d-4a5c-82c0-21d40ffdbf4f/76183693221.pdf
- https://site-1040203.mozfiles.com/files/1040203/14233231579.pdf
- https://site-1044197.mozfiles.com/files/1044197/candy_crush_friends_saga_latest_mod_apk.pdf
- https://cdn-cms.f-static.net/uploads/4365639/normal_5f871a8e3f9b5.pdf
- https://cdn-cms.f-static.net/uploads/4366365/normal_5f870ee590070.pdf
- https://cdn.shopify.com/s/files/1/0434/8854/2872/files/sudaxidavobuloxogeta.pdf
- https://cdn.shopify.com/s/files/1/0429/6740/0601/files/tamaxuf.pdf
- https://uploads.strikinglycdn.com/files/ce8cf2e0-0c50-46af-b606-c7006f373e74/barewalufekivowori.pdf
- https://uploads.strikinglycdn.com/files/438247b6-5c9a-4291-a960-f53a1a89a4f7/setazu.pdf
- https://uploads.strikinglycdn.com/files/91b98693-41c9-4cfc-aa5f-0f9961718b18/46113182272.pdf
- https://uploads.strikinglycdn.com/files/ab760ee2-70eb-4901-9559-6b25a4466846/78754350844.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- xojerajap.weebly.com
- jakedekokobara.weebly.com
- ruwopevod.weebly.com
- uploads.strikinglycdn.com
- site-1040203.mozfiles.com
- site-1044197.mozfiles.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report