MALICIOUS — 7052517.pdf
MALICIOUS — 7052517.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7db8e98c60f8380cbefc233a6668c028fb91edd1979f7350f113a04dddca4b62 - SHA-1:
9056594aa298e4c725049303f326ebe3e9877a20 - MD5:
49f09e349cd188caa05311982d4c1b66 - ssdeep:
768:ggGzpDcpOvizpQ5c2Pzm8yBInyg6MJZe73Q8SS3s748YJK:tGFgp2izpnHIntZY3yS3s748kK - TLSH:
T1C3327EF350A7EE4C768F6703A9AB02695489D789A137D7A0418C6B2CC07CAFD7F10651 - Submitted as: 7052517.pdf
- File type: pdf · Size: 43455 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/7bf01a8e81.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=sailor%20moon%20video%20games, https://site-1038442.mozfiles.com/files/1038442/26567975984.pdf, https://site-1040424.mozfiles.com/files/1040424/xowasarijedeluz.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=sailor%20moon%20video%20games
- https://site-1038442.mozfiles.com/files/1038442/26567975984.pdf
- https://site-1040424.mozfiles.com/files/1040424/xowasarijedeluz.pdf
- https://site-1042620.mozfiles.com/files/1042620/kuwubapafokupovodok.pdf
- https://site-1037141.mozfiles.com/files/1037141/26199447257.pdf
- https://site-1039570.mozfiles.com/files/1039570/fajinusufiretusenuxajub.pdf
- https://site-1037870.mozfiles.com/files/1037870/nosobalina.pdf
- https://site-1036646.mozfiles.com/files/1036646/lojijavobuxedixeb.pdf
- https://site-1039494.mozfiles.com/files/1039494/modern_compressible_flow_anderson_solution.pdf
- https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/7bf01a8e81.pdf
- https://vevejeda.weebly.com/uploads/1/3/0/7/130776099/xopevaxeluvakik.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/vunidixeviro_xitosujitupile_kadape.pdf
- https://jabiratunibi.weebly.com/uploads/1/3/2/6/132683422/835af5.pdf
- https://xazapadikud.weebly.com/uploads/1/3/1/8/131871762/019da7bcb.pdf
- https://uploads.strikinglycdn.com/files/574fc624-6aa4-4b34-a9b3-54404cf8827b/zenerukerikewifok.pdf
- https://uploads.strikinglycdn.com/files/8c9c97fd-bcd1-40fe-a161-ea2fba36e858/25399790679.pdf
- https://uploads.strikinglycdn.com/files/b311468c-14d9-43f2-8985-7e797a9a273f/motodibejoviwizop.pdf
- https://uploads.strikinglycdn.com/files/489d6bcd-0229-4b33-ae5f-d08449768480/kesizoririlosa.pdf
- https://uploads.strikinglycdn.com/files/a1e1ff39-adcd-4ad4-95c9-9f88f1897461/81638534641.pdf
- https://uploads.strikinglycdn.com/files/d1203e11-b1e0-432a-8f86-5579aa76b9b4/wizudebofux.pdf
- https://uploads.strikinglycdn.com/files/ed439194-7cff-490b-af3e-3d5634744ba0/ranebamodez.pdf
- https://uploads.strikinglycdn.com/files/538055ff-1325-4abe-a08e-125716655096/xusitojujo.pdf
- https://cdn-cms.f-static.net/uploads/4368951/normal_5f87a0fb6337b.pdf
- https://cdn-cms.f-static.net/uploads/4366664/normal_5f87816461a21.pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f870f9c1e63e.pdf
Embedded domains
- cctraff.ru
- site-1038442.mozfiles.com
- site-1040424.mozfiles.com
- site-1042620.mozfiles.com
- site-1037141.mozfiles.com
- site-1039570.mozfiles.com
- site-1037870.mozfiles.com
- site-1036646.mozfiles.com
- site-1039494.mozfiles.com
- pigogokeda.weebly.com
- vevejeda.weebly.com
- bedizegoresupa.weebly.com
- jabiratunibi.weebly.com
- xazapadikud.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report