MALICIOUS — 9863913.pdf
MALICIOUS — 9863913.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
994e045cd6598f7e2f6d780b1d201d8911f1c89ae33b2b455e1d381b70a3548c - SHA-1:
61eb206e761736d7fa2d62863cd9f6e4664ff82a - MD5:
c5cf7ef213472e4bcb53a4090b531a30 - ssdeep:
768:kgGzpDQpkRxWbsciFdANUeNxotTIe6Q8ORy2zcO7OZwqhaG:RGFEpmVHkOeNyCQswcO7OHhaG - TLSH:
T182339EF310E7ED8C399BAF079AAA1199518ED788A136D7A0448C773C847C6FD6E01A11 - Submitted as: 9863913.pdf
- File type: pdf · Size: 50652 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/zidebesirolabavo.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=insanity%20clicker%20guide, https://ruwopevod.weebly.com/uploads/1/3/1/3/131397973/0c7de.pdf, https://jezaxegare.weebly.com/uploads/1/3/1/3/131380636/305207.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=insanity%20clicker%20guide
- https://ruwopevod.weebly.com/uploads/1/3/1/3/131397973/0c7de.pdf
- https://jezaxegare.weebly.com/uploads/1/3/1/3/131380636/305207.pdf
- https://xodetawutal.weebly.com/uploads/1/3/0/7/130774968/5713232.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/zidebesirolabavo.pdf
- https://uploads.strikinglycdn.com/files/9b932fa5-f9e7-409c-ae85-d7342c0a8976/45490630874.pdf
- https://uploads.strikinglycdn.com/files/067777a9-14a8-4d7b-9abb-60f0e444efc9/384674713.pdf
- https://uploads.strikinglycdn.com/files/2a091827-9df2-43a0-9adc-8ea6ea9f0104/limiguxopesedadujika.pdf
- https://uploads.strikinglycdn.com/files/df1de363-cd76-444e-a841-165b54b926e7/14009250865.pdf
- https://gozofuma.weebly.com/uploads/1/3/0/8/130874065/gopelobudava.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/rebodi.pdf
- https://wavuvavezexa.weebly.com/uploads/1/3/0/7/130775629/8b4a76414c296ba.pdf
- https://rezizeme.weebly.com/uploads/1/3/0/7/130775554/aaa1b366bd7fe.pdf
- https://uploads.strikinglycdn.com/files/9c1ba8ca-b450-46d3-9fce-d5735f4b78c6/i_know_that_my_redeemer_lives_sheet_music_duet.pdf
- https://uploads.strikinglycdn.com/files/beab53da-e442-40d5-90b5-b3e7ce7e194f/64233340887.pdf
- https://uploads.strikinglycdn.com/files/e4a9f14a-40ac-4c5f-a993-176095b569ac/22261599466.pdf
- https://uploads.strikinglycdn.com/files/c3a991a2-dad9-411a-81c9-f418d678fc86/35300256837.pdf
- https://uploads.strikinglycdn.com/files/b94a6852-a02b-44be-bb01-622069556a9e/7224056582.pdf
- https://cdn.shopify.com/s/files/1/0433/4449/4750/files/based_on_the_pure_expectations_theory.pdf
- https://cdn.shopify.com/s/files/1/0478/3013/9039/files/bonsai_apple_tree_growing_a_full-sized_apple.pdf
- https://uploads.strikinglycdn.com/files/59da3fec-1683-4d53-8066-46a807d1b35b/sarah_wilson_i_quit_sugar.pdf
- https://uploads.strikinglycdn.com/files/04f06564-7b8a-4f6e-9d91-87f1e2a5c653/98751921499.pdf
- https://uploads.strikinglycdn.com/files/8da77022-fed1-4bc5-8c3f-38f0d9d72661/wudipuvejaxukutivuginalas.pdf
- https://uploads.strikinglycdn.com/files/1024a293-6fca-4ed8-868b-f187fa9e7323/varoxixomijaxikilaruba.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- ruwopevod.weebly.com
- jezaxegare.weebly.com
- xodetawutal.weebly.com
- jawasolasazilem.weebly.com
- uploads.strikinglycdn.com
- gozofuma.weebly.com
- jatorogerujew.weebly.com
- wavuvavezexa.weebly.com
- rezizeme.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report