MALICIOUS — 7008435.pdf
MALICIOUS — 7008435.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
81d5a1c03e6ac6051224c679e7e1eb94c487807027d8282b580688fded214744 - SHA-1:
7bf677a8f4115140d6eb141d14c121bf6c04bb95 - MD5:
f5415b0ff1781bec8ab094c03b14073c - ssdeep:
768:ZgGzpDLp8fFBf+6+yaLpbXs+G+uMstjxpoahG2zFld2lxd+/JuGEjEUb5ESw0:aGFPpkWQ+xGlxpoX2Jld2lxdiJrEB5EM - TLSH:
T1F6328DF340D3DE8CBA478B13ADBB2169A185C648A237D790445C366DD0BCABE7E00971 - Submitted as: 7008435.pdf
- File type: pdf · Size: 47467 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://cdn-cms.f-static.net/uploads/4367275/normal_5f874afbd1d94.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=briggs%20and%20stratton%20repair%20manual%20ms-9856, https://cdn-cms.f-static.net/uploads/4367275/normal_5f874afbd1d94.pdf, https://cdn-cms.f-static.net/uploads/4366366/normal_5f87203eec8cc.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=briggs%20and%20stratton%20repair%20manual%20ms-9856
- https://cdn-cms.f-static.net/uploads/4367275/normal_5f874afbd1d94.pdf
- https://cdn-cms.f-static.net/uploads/4366366/normal_5f87203eec8cc.pdf
- https://cdn-cms.f-static.net/uploads/4366362/normal_5f87237ba7777.pdf
- https://cdn-cms.f-static.net/uploads/4365602/normal_5f8700c1397e1.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/1158663.pdf
- https://tajurasexir.weebly.com/uploads/1/3/1/6/131606020/tufifejus_juwugotelakug_jemibil.pdf
- https://rimesozarabef.weebly.com/uploads/1/3/1/6/131607712/mojudedosi_gugakazeno.pdf
- https://zulatikuwa.weebly.com/uploads/1/3/0/7/130776211/dea39d12.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/wubogovexipipeweta.pdf
- https://uploads.strikinglycdn.com/files/26a99da5-2620-4f95-a70d-f0d2b014d277/tufejedu.pdf
- https://uploads.strikinglycdn.com/files/2435551e-a694-4d63-983a-164ddc6aa209/97541049851.pdf
- https://uploads.strikinglycdn.com/files/fb29c217-ec38-4f20-a8c4-02e14c3e5852/fusafezefotizuvas.pdf
- https://uploads.strikinglycdn.com/files/ab027de0-0c42-408e-b586-729b1798d117/42555463144.pdf
- https://uploads.strikinglycdn.com/files/46c78fa8-b8f3-4b83-b4a6-e04ad65dd975/55987388631.pdf
- https://cdn-cms.f-static.net/uploads/4365624/normal_5f8735d4d2156.pdf
- https://cdn-cms.f-static.net/uploads/4366359/normal_5f8750c5f3eaf.pdf
- https://cdn-cms.f-static.net/uploads/4365639/normal_5f86f457325c8.pdf
- https://cdn-cms.f-static.net/uploads/4366371/normal_5f874bbc7fef6.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f87243a9d98c.pdf
- https://site-1037081.mozfiles.com/files/1037081/xogoguzazedapigofeg.pdf
- https://site-1039420.mozfiles.com/files/1039420/mepodavevexota.pdf
- https://site-1038679.mozfiles.com/files/1038679/32809426612.pdf
- https://site-1044148.mozfiles.com/files/1044148/72943707028.pdf
- https://site-1039174.mozfiles.com/files/1039174/23084043914.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- dutitujazekap.weebly.com
- tajurasexir.weebly.com
- rimesozarabef.weebly.com
- zulatikuwa.weebly.com
- wepugimi.weebly.com
- uploads.strikinglycdn.com
- site-1037081.mozfiles.com
- site-1039420.mozfiles.com
- site-1038679.mozfiles.com
- site-1044148.mozfiles.com
- site-1039174.mozfiles.com
- wuvirinofibugiz.weebly.com
- vibebivenef.weebly.com
- sesuwulot.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report