MALICIOUS — 41eee.pdf
MALICIOUS — 41eee.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a0498e0e36980e89345426d959523e9530102c827cd86f549c27d328a80bc14f - SHA-1:
ccd5aff04b6f9a40dabf200dda0c8b6964d47872 - MD5:
ea09404027e526bcab2f6ed3547d47fb - ssdeep:
768:VgGzpDFpypH4Z321iFaR8uaqmh9wwF1dqBpiX7nxrfTda+Ezw0MIBggXFSz:GGF5plVn3PwwFnqHunVfTRsggXFSz - TLSH:
T1AA339DF350D7ED4CBB8A5B03ADEB049A6149C38DA13AE790449C6B3DC47C6AD6E10851 - Submitted as: 41eee.pdf
- File type: pdf · Size: 51805 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/91fc9d55-c359-4891-9ec6-f3e9163bff5d/buvurob.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=comptia%20security%20study%20guide%20ebook, https://uploads.strikinglycdn.com/files/91fc9d55-c359-4891-9ec6-f3e9163bff5d/buvurob.pdf, https://uploads.strikinglycdn.com/files/cfd458bf-6a73-464f-a13b-2e9186c1ad77/74153892939.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=comptia%20security%20study%20guide%20ebook
- https://uploads.strikinglycdn.com/files/91fc9d55-c359-4891-9ec6-f3e9163bff5d/buvurob.pdf
- https://uploads.strikinglycdn.com/files/cfd458bf-6a73-464f-a13b-2e9186c1ad77/74153892939.pdf
- https://uploads.strikinglycdn.com/files/3acec33a-c98a-40f8-ab68-f3ec1a25a521/36315441169.pdf
- https://uploads.strikinglycdn.com/files/57cf4ec9-8923-4859-b690-da426ba894aa/98728215222.pdf
- https://uploads.strikinglycdn.com/files/8e0eb054-6825-4f0f-8a28-8af6febd695a/pebipekozobiwogadu.pdf
- https://cdn-cms.f-static.net/uploads/4366400/normal_5f87438ae46c3.pdf
- https://cdn-cms.f-static.net/uploads/4365619/normal_5f8716695403f.pdf
- https://cdn-cms.f-static.net/uploads/4366969/normal_5f873fc4a5b8b.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f875c914f591.pdf
- https://cdn.shopify.com/s/files/1/0495/6530/2936/files/jogalozomugusezin.pdf
- https://cdn.shopify.com/s/files/1/0266/9661/4068/files/geary_county_jail_inmates.pdf
- https://cdn.shopify.com/s/files/1/0432/0090/5380/files/kaplan_usmle_step_1_qbook.pdf
- https://cdn.shopify.com/s/files/1/0496/3673/7177/files/pest_control_notice_sample_letter.pdf
- https://cdn.shopify.com/s/files/1/0482/1522/8570/files/fuvedosovitegujunumezi.pdf
- https://uploads.strikinglycdn.com/files/939b50b5-b6d6-4fe8-85ee-38789d3165c8/rakodo.pdf
- https://uploads.strikinglycdn.com/files/7d3025f6-8dc0-45e5-80af-75581c2ec95a/34884396781.pdf
- https://uploads.strikinglycdn.com/files/f35e909a-78e3-4014-97b1-e716ec27687b/81061835374.pdf
- https://uploads.strikinglycdn.com/files/1dc4b44a-d39f-4ae4-8757-b15818d1216f/nujopovuxekamusefagupez.pdf
- https://site-1043582.mozfiles.com/files/1043582/7887871288.pdf
- https://site-1040884.mozfiles.com/files/1040884/37875387988.pdf
- https://site-1037251.mozfiles.com/files/1037251/jaxejonadenu.pdf
- https://site-1038988.mozfiles.com/files/1038988/ruverelikozatelane.pdf
- https://site-1038313.mozfiles.com/files/1038313/17026741209.pdf
- https://vuzevarezevarot.weebly.com/uploads/1/3/0/7/130740461/37288358.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1043582.mozfiles.com
- site-1040884.mozfiles.com
- site-1037251.mozfiles.com
- site-1038988.mozfiles.com
- site-1038313.mozfiles.com
- vuzevarezevarot.weebly.com
- debasomi.weebly.com
- waniremupamed.weebly.com
- genigudepa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report