MALICIOUS — 74169771390.pdf
MALICIOUS — 74169771390.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9b8da5ae6ae622ac447541c64e02d5fb14f77aec660b2f6c51138a2d6374184f - SHA-1:
b9eb51afa8682b5d551016aa5defa759f3885d36 - MD5:
6fc479739e53fb6b2cf51f6b779cafe6 - ssdeep:
768:+gGzpDUpeoepsXQBXbxE8QF+y6l+Xcfae+ukAvpYNp1x0Z7Mg23k1y8a:7GFwpe9kqflsvAvqp1OZIfk1y8a - TLSH:
T118319CF748A7EC8C7E87AB135CFA1515658AD38D6232D7A0488C727DC4BC5BC6E10860 - Submitted as: 74169771390.pdf
- File type: pdf · Size: 42533 bytes
- Verdict: malicious (75/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/godekux.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=long+distance+real+estate+investing+pdf, https://cdn-cms.f-static.net/uploads/4366036/normal_5f8734018aeee.pdf, https://cdn-cms.f-static.net/uploads/4389107/normal_5f8f3ecce4431.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=long+distance+real+estate+investing+pdf
- https://cdn-cms.f-static.net/uploads/4366036/normal_5f8734018aeee.pdf
- https://cdn-cms.f-static.net/uploads/4389107/normal_5f8f3ecce4431.pdf
- https://cdn-cms.f-static.net/uploads/4365599/normal_5f872fc2021c1.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/novovuxosijuzuz_wofabunutigepuw_dugulelura.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/godekux.pdf
- https://kuromazu.weebly.com/uploads/1/3/2/6/132695519/205a6c6c3e.pdf
- https://cdn.shopify.com/s/files/1/0496/0744/2584/files/kizivujokexazasavivusew.pdf
- https://cdn.shopify.com/s/files/1/0499/2991/2488/files/kusezonomen.pdf
- https://cdn.shopify.com/s/files/1/0429/6399/2742/files/wagolejaseze.pdf
- https://uploads.strikinglycdn.com/files/e070823b-27ba-486a-8d52-7b75ec9003d5/8000883212.pdf
- https://uploads.strikinglycdn.com/files/5ab4b936-636a-492b-8cb5-9dd1013ad40a/26731043293.pdf
- https://uploads.strikinglycdn.com/files/715232a0-b6a3-41ab-8184-79af5a06028d/wopugovoxukulotaz.pdf
- https://uploads.strikinglycdn.com/files/69e2f371-7779-4f75-bddc-019868680c5c/xazuwogikelalar.pdf
- https://uploads.strikinglycdn.com/files/69457973-be64-4d49-a9b6-db4e721054db/talobifeboxupotidisase.pdf
- https://uploads.strikinglycdn.com/files/6ce62153-665a-401a-9804-d8a80e67f5c5/3133139869.pdf
- https://uploads.strikinglycdn.com/files/e7062941-b242-4682-beb3-7b518f4f4d7a/kusazaketuburixupomoxib.pdf
- https://uploads.strikinglycdn.com/files/48dfb0e5-a5db-4d47-b902-4a1af4ba9d3c/93391224462.pdf
- https://uploads.strikinglycdn.com/files/3b8d35a8-9284-4f10-afb0-1f47ce68f038/67927121506.pdf
- https://uploads.strikinglycdn.com/files/a3114cc3-ad6b-4940-9264-130a3cbb0b29/92659101338.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- gimejexoxixaza.weebly.com
- jakedekokobara.weebly.com
- kuromazu.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report