MALICIOUS — 8674780.pdf
MALICIOUS — 8674780.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
964a43ac8bef6e33199a5ceb94e1ce9664c1a0adf535b96b552c53f92c39eb39 - SHA-1:
511912d0d008def9daf231ad28273ffa9e7bbe72 - MD5:
25cb94f866407b28868b7051656d35b7 - ssdeep:
1536:fGFdpT24+76ah+mHmt1TlvZuSE9qrJn2zqyj:OFdpK4+ODmGt15vM7qFnGq6 - TLSH:
T1A7338EF34057FE8C7A4E6B03ADEB1199558EC38D6176D790458C2B2CC4BC6EE2E10A64 - Submitted as: 8674780.pdf
- File type: pdf · Size: 49841 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://nogomikosisodop.weebly.com/uploads/1/3/2/6/132681488/vajupoxakobotoga.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=daa%20enteral%20feeding%20manual%20for%20adults%20in%20healthcare%20facilities, https://nogomikosisodop.weebly.com/uploads/1/3/2/6/132681488/vajupoxakobotoga.pdf, https://bizetuxerupa.weebly.com/uploads/1/3/0/8/130873791/velazibukawaj_jixizelefujofek_pugafizu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=daa%20enteral%20feeding%20manual%20for%20adults%20in%20healthcare%20facilities
- https://nogomikosisodop.weebly.com/uploads/1/3/2/6/132681488/vajupoxakobotoga.pdf
- https://bizetuxerupa.weebly.com/uploads/1/3/0/8/130873791/velazibukawaj_jixizelefujofek_pugafizu.pdf
- https://pozosukezogi.weebly.com/uploads/1/3/4/3/134386022/kuteme_menonumibamami_fepafaxukabu.pdf
- https://zeronifoza.weebly.com/uploads/1/3/4/3/134312515/6272549.pdf
- https://sanuvexugivi.weebly.com/uploads/1/3/1/6/131606490/gabakovolobi_jadezoranededo_pamomug.pdf
- https://jowodetuleguzu.weebly.com/uploads/1/3/1/8/131856173/2e884.pdf
- https://bizumoku.weebly.com/uploads/1/3/2/6/132681494/wafubaduxave-kataweko.pdf
- https://cdn.shopify.com/s/files/1/0499/4246/2618/files/kotisuga.pdf
- https://cdn.shopify.com/s/files/1/0440/5588/8022/files/nra_basic_pistol_course_manual.pdf
- https://cdn.shopify.com/s/files/1/0430/7877/9047/files/ruvalamilemepuvu.pdf
- https://cdn.shopify.com/s/files/1/0434/6249/2324/files/turuxadakolawazulugataj.pdf
- https://cdn.shopify.com/s/files/1/0495/2214/7494/files/red_devil_cichlid.pdf
- https://cdn.shopify.com/s/files/1/0480/5312/5284/files/wanuxejagisavijutimox.pdf
- https://cdn.shopify.com/s/files/1/0428/4655/2227/files/95414483465.pdf
- https://cdn.shopify.com/s/files/1/0435/2724/1879/files/contact_angle_wettability_and_adhesion.pdf
- https://cdn-cms.f-static.net/uploads/4366984/normal_5f8ad549074f7.pdf
- https://cdn-cms.f-static.net/uploads/4390661/normal_5f92095d2c28b.pdf
- https://cdn-cms.f-static.net/uploads/4369907/normal_5f8dbbf79e26c.pdf
- https://cdn-cms.f-static.net/uploads/4366395/normal_5f8d387cc2acc.pdf
- https://cdn-cms.f-static.net/uploads/4365653/normal_5f8760ae5d57a.pdf
- https://uploads.strikinglycdn.com/files/ecdf30a7-22d8-4e69-abe1-ad31ef2d9564/sunox.pdf
- https://uploads.strikinglycdn.com/files/3da0c9f2-7c10-45f4-833d-f795300031f8/barigopula.pdf
- https://uploads.strikinglycdn.com/files/7825ba31-2fa1-4079-a55a-e4253228d24e/wedding_march_piano_easy_free_download.pdf
- https://uploads.strikinglycdn.com/files/88ad1996-e7e6-4e11-b276-2196295ed3b7/52663795320.pdf
Embedded domains
- cctraff.ru
- nogomikosisodop.weebly.com
- bizetuxerupa.weebly.com
- pozosukezogi.weebly.com
- zeronifoza.weebly.com
- sanuvexugivi.weebly.com
- jowodetuleguzu.weebly.com
- bizumoku.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report