MALICIOUS — 07393493.pdf
MALICIOUS — 07393493.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b420065dc0496c194c1564f901949f41ce7952be18af81e91ec98692d946a515 - SHA-1:
a3a8530941fe1904090be065fe09bf452577a86c - MD5:
88d34ffea8728a9eef260dba2138fafe - ssdeep:
768:kgGzpDzeui5kncvfESk44ivOmQu7lwAkDsiQ92TrBKwX/LPy6VGS1:RGFfeufhSkKvpQueZsiQGrBKwXjqcGS1 - TLSH:
T172328DF310E7DD8DBA8BAB03EEBB10A9218EC7486136D750458CB62DD57C6AD7D10920 - Submitted as: 07393493.pdf
- File type: pdf · Size: 47179 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/busixakowun_zefisuni.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=amores%20perros%20control%20machete%20mp3%20download, https://uploads.strikinglycdn.com/files/1d430480-2c9d-49ed-a386-b0bc325fbd95/sadaja.pdf, https://uploads.strikinglycdn.com/files/015d36c4-f70b-4cfb-8da7-7768f4d52e06/25355716392.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=amores%20perros%20control%20machete%20mp3%20download
- https://uploads.strikinglycdn.com/files/1d430480-2c9d-49ed-a386-b0bc325fbd95/sadaja.pdf
- https://uploads.strikinglycdn.com/files/015d36c4-f70b-4cfb-8da7-7768f4d52e06/25355716392.pdf
- https://uploads.strikinglycdn.com/files/b6df0322-a88f-467d-888b-3a6c4ada0cf5/38207550996.pdf
- https://uploads.strikinglycdn.com/files/b1940ead-1759-407e-8d54-6a23c698926f/36510378250.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/tebavu_mofevuz_punoxibera_gijipomole.pdf
- https://xubuvene.weebly.com/uploads/1/3/1/3/131380433/2275779.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/busixakowun_zefisuni.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/jinitorip-bolag.pdf
- https://uploads.strikinglycdn.com/files/da40f575-eece-43cd-b6a5-4398a515a695/23819241820.pdf
- https://uploads.strikinglycdn.com/files/b5b35a8c-1bb6-445b-b0a4-6a187510dd94/tibumubasot.pdf
- https://uploads.strikinglycdn.com/files/78e92af6-ae76-4df2-b4fd-81371ae3675f/buzanatimog.pdf
- https://uploads.strikinglycdn.com/files/0c4beedf-7491-4c0d-b69e-2da1a27fd216/90764846784.pdf
- https://uploads.strikinglycdn.com/files/874b6c2c-2ff8-40dc-952f-964e9cf9472b/xejonibuxupel.pdf
- https://site-1043519.mozfiles.com/files/1043519/83797605247.pdf
- https://site-1039932.mozfiles.com/files/1039932/pigojub.pdf
- https://site-1039923.mozfiles.com/files/1039923/share_wifi_from_your_android_phone.pdf
- https://site-1043607.mozfiles.com/files/1043607/29519957565.pdf
- https://site-1045390.mozfiles.com/files/1045390/71097149367.pdf
- https://cdn.shopify.com/s/files/1/0268/8758/5989/files/shadowfang_keep_level_classic.pdf
- https://cdn.shopify.com/s/files/1/0484/8979/1643/files/46727174712.pdf
- https://cdn.shopify.com/s/files/1/0434/6868/5464/files/bully_scholarship_edition_android_apkdata.pdf
- https://uploads.strikinglycdn.com/files/5dad387e-e1cb-4ef4-996b-ba6ca71f0144/4646764685.pdf
- https://uploads.strikinglycdn.com/files/15e8e074-2618-4661-9fa3-bf864f957302/xamipamizugofedo.pdf
- https://uploads.strikinglycdn.com/files/43129064-7799-4866-930e-cf475e9fe107/kopitaneboxijizegus.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- keniwuki.weebly.com
- xubuvene.weebly.com
- jakedekokobara.weebly.com
- gimejexoxixaza.weebly.com
- site-1043519.mozfiles.com
- site-1039932.mozfiles.com
- site-1039923.mozfiles.com
- site-1043607.mozfiles.com
- site-1045390.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report