MALICIOUS — afbd779ea0a.pdf
MALICIOUS — afbd779ea0a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8641d0dba803d73aebadec21d09eea53ebac63786582ac5f5500a2de6061ed53 - SHA-1:
821bc192b51cea92b36f09fd9a690c4153f43213 - MD5:
1e5449d8c55d5a647e850a56349cd0f0 - ssdeep:
768:QgGzpDOpARHik18BJf0rtlDoxiX9xWe9p68AiglsNpMClxTSfz5z6kR/Vhage:9GFCpB7e9htxNpMCLSfooVhage - TLSH:
T134328DF35097ED8C7A8F5B43AEEA1199A149D2886233A75015C8631CD47CAFE3F10A61 - Submitted as: afbd779ea0a.pdf
- File type: pdf · Size: 46085 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/d1ee3c84.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=evaluation%20pluriel%20des%20noms%20ce2, https://cdn.shopify.com/s/files/1/0484/4512/8858/files/vejafodapazoxe.pdf, https://cdn.shopify.com/s/files/1/0431/4749/3536/files/22389355193.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=evaluation%20pluriel%20des%20noms%20ce2
- https://cdn.shopify.com/s/files/1/0500/2048/3232/files/chapter_15_to_kill_a_mockingbird_literary_devices.pdf
- https://cdn.shopify.com/s/files/1/0484/4512/8858/files/vejafodapazoxe.pdf
- https://cdn.shopify.com/s/files/1/0431/4749/3536/files/22389355193.pdf
- https://cdn.shopify.com/s/files/1/0501/4247/8501/files/51397976950.pdf
- https://cdn.shopify.com/s/files/1/0266/7810/0146/files/wheatland_mo_public_school.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/d1ee3c84.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/sanufiruwula-nuxagadedanureg.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/3373854.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/laresisif_kigadebokenub_bajutinerid.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/runemevurexuziwone.pdf
- https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/kurufe_devomikata.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/letizokukuwa.pdf
- https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/gabemomigipenaguv.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/monirafulowafix.pdf
- https://cdn.shopify.com/s/files/1/0431/3595/9202/files/berea_middle_school_ky.pdf
- https://cdn.shopify.com/s/files/1/0431/4660/8794/files/zifexulekaro.pdf
- https://cdn.shopify.com/s/files/1/0497/8468/4706/files/2115685533.pdf
- https://cdn.shopify.com/s/files/1/0496/5924/8797/files/tubemate_apk_android_download_free.pdf
- https://cdn.shopify.com/s/files/1/0482/0808/5144/files/23151665313.pdf
- https://cdn.shopify.com/s/files/1/0496/5833/1300/files/dont_fence_me_in_lyrics_roy_rogers.pdf
- https://site-1039426.mozfiles.com/files/1039426/43529572021.pdf
- https://site-1038954.mozfiles.com/files/1038954/75741692601.pdf
- https://site-1042287.mozfiles.com/files/1042287/49334222624.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- cdn.shopify.com
- jawasolasazilem.weebly.com
- wepugimi.weebly.com
- xojerajap.weebly.com
- genigudepa.weebly.com
- sesuwulot.weebly.com
- kabudededawizo.weebly.com
- gimejexoxixaza.weebly.com
- site-1039426.mozfiles.com
- site-1038954.mozfiles.com
- site-1042287.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report