MALICIOUS — 3536365987.pdf
MALICIOUS — 3536365987.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a7cbeee57ca5c64e6562cb109146f471f8017ec5624505af59a32b6968d8eea5 - SHA-1:
f35cdc7a46a225efa57897c3baf2263f3a625041 - MD5:
bbff2ab5e1518f803d9c08c85ccad7a0 - ssdeep:
768:wgGzpDjelMwgLZ7L8rJfqHeGtoFBHM7feo1c1yzHMa70qfwPCoQzUHH/k5f/QgY7:dGFneBrJf+HMa7dwPCXUsdTh+0rI - TLSH:
T1F3338EF340A7EC8C7ACF6B4369A71559618AD74DA0239761059C773CC4BC6FE2E00652 - Submitted as: 3536365987.pdf
- File type: pdf · Size: 49481 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://mojenosude.weebly.com/uploads/1/3/1/3/131382274/3837160.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=girl.on+the+train+book, https://mojenosude.weebly.com/uploads/1/3/1/3/131382274/3837160.pdf, https://rabugotekinevod.weebly.com/uploads/1/3/1/8/131871666/7424962.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=girl.on+the+train+book
- https://s3.amazonaws.com/memul/distress_tolerance_scale_dts.pdf
- https://s3.amazonaws.com/subud/zadodidubisedalifij.pdf
- https://s3.amazonaws.com/jamokaroxoj/xatesavafamadur.pdf
- https://mojenosude.weebly.com/uploads/1/3/1/3/131382274/3837160.pdf
- https://rabugotekinevod.weebly.com/uploads/1/3/1/8/131871666/7424962.pdf
- https://gemenudotipetal.weebly.com/uploads/1/3/2/6/132695720/lopaxarusiw.pdf
- https://wozofawado.weebly.com/uploads/1/3/0/8/130874325/6681048.pdf
- https://cdn.shopify.com/s/files/1/0487/7261/2262/files/duracell_ion_speed_4000_battery_charger_manual.pdf
- https://cdn.shopify.com/s/files/1/0479/1654/8262/files/zodudopawima.pdf
- https://cdn.shopify.com/s/files/1/0498/0611/4978/files/17943629343.pdf
- https://cdn.shopify.com/s/files/1/0438/2231/7728/files/45726610009.pdf
- https://cdn.shopify.com/s/files/1/0439/0515/5227/files/51025474952.pdf
- https://cdn-cms.f-static.net/uploads/4368782/normal_5f878190e0285.pdf
- https://cdn-cms.f-static.net/uploads/4365652/normal_5f8754416ebb6.pdf
- https://cdn-cms.f-static.net/uploads/4365656/normal_5f88b24559a76.pdf
- https://cdn-cms.f-static.net/uploads/4365576/normal_5f8e6f3a33e10.pdf
- https://cdn.shopify.com/s/files/1/0483/5331/2928/files/honda_generator_eu2000i_parts_manual.pdf
- https://cdn.shopify.com/s/files/1/0430/8523/4338/files/kigetinuwaxavowe.pdf
- https://cdn.shopify.com/s/files/1/0437/9879/0301/files/pezosofedefugositekokul.pdf
- https://cdn.shopify.com/s/files/1/0484/7036/0225/files/seminole_county_public_schools_calendar_2021.pdf
- https://cdn.shopify.com/s/files/1/0480/2812/3295/files/wekawokuxamigika.pdf
- https://cdn.shopify.com/s/files/1/0437/6035/3429/files/denyo_welding_generator_manual.pdf
- https://cdn.shopify.com/s/files/1/0486/3872/2206/files/cookie_clicker_easter_last_egg.pdf
- https://cdn.shopify.com/s/files/1/0268/7536/3504/files/income_guidelines_for_medicaid_in_michigan_2020.pdf
Embedded domains
- ggtraff.ru
- s3.amazonaws.com
- mojenosude.weebly.com
- rabugotekinevod.weebly.com
- gemenudotipetal.weebly.com
- wozofawado.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report