MALICIOUS — desox.pdf
MALICIOUS — desox.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b320093f82889deabe319fc09fcb9471ea294f0a11a3214f3c7e6546f3037504 - SHA-1:
e4b73aec38ee8ab1222d55fef983590c9a58fc57 - MD5:
9f01ac764bf264291933963fa57039d4 - ssdeep:
768:eygGzpDgQW72iZuUxb9oGxsTxBq4dzGZvCfxCOkHNF:UGF0J2iZ9xxsT+wzGZa4rHNF - TLSH:
T1E9329DF360A7DD4CBB86AB17A9F60458614A8B4C60279AB055987B7CD0BC6FD6F00E10 - Submitted as: desox.pdf
- File type: pdf · Size: 43786 bytes
- Verdict: malicious (75/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/ce9df12f-4cc5-40f8-88d2-0c0b9165a51b/rinoxutipidirejuv.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=addition+worksheets+for+first+grade+pdf, https://uploads.strikinglycdn.com/files/ce9df12f-4cc5-40f8-88d2-0c0b9165a51b/rinoxutipidirejuv.pdf, https://uploads.strikinglycdn.com/files/50c153a2-e9eb-461c-998e-922d2379a6f8/14856689061.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=addition+worksheets+for+first+grade+pdf
- https://uploads.strikinglycdn.com/files/ce9df12f-4cc5-40f8-88d2-0c0b9165a51b/rinoxutipidirejuv.pdf
- https://uploads.strikinglycdn.com/files/50c153a2-e9eb-461c-998e-922d2379a6f8/14856689061.pdf
- https://uploads.strikinglycdn.com/files/b0780dd3-097d-4905-ab96-317bcff95c95/momizibaxiku.pdf
- https://uploads.strikinglycdn.com/files/6404fa51-45a4-480f-8f4b-03c8390ed14f/ruxadefume.pdf
- https://uploads.strikinglycdn.com/files/6535ee19-2bbe-4a79-8bdd-fd6c3be5e9dd/45873554083.pdf
- https://uploads.strikinglycdn.com/files/7e95ee3d-9baa-4cb2-b9f7-49daa0e39963/kasuwukasifuvebe.pdf
- https://uploads.strikinglycdn.com/files/1c68c966-422d-4b93-9fd4-24ff0016b3b7/29879749276.pdf
- https://uploads.strikinglycdn.com/files/3d968587-dd95-420f-ab06-efdfbc15ec41/47853683921.pdf
- https://uploads.strikinglycdn.com/files/af294e59-1180-43d8-82bf-f59da0775e04/bivixazajatusorififipaga.pdf
- https://uploads.strikinglycdn.com/files/a3090f0e-56f9-4a08-92f9-173804c27b06/56407668499.pdf
- https://uploads.strikinglycdn.com/files/8c470927-208b-4e50-abda-ed07785d935d/70706422648.pdf
- https://uploads.strikinglycdn.com/files/7f915770-6d23-4eb5-8ac8-99f4449dee39/fokuleverusisarefafe.pdf
- https://uploads.strikinglycdn.com/files/32a06353-e570-45ae-b9f8-fcad0c725657/99061666498.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report