MALICIOUS — 9325658.pdf
MALICIOUS — 9325658.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b439066031fdf9eaeacc9b934503340234fefb781890bce70f09755e6d43fec9 - SHA-1:
41e5fea31c35b0748aef0df853673e834c8e4ac2 - MD5:
866dbb54acd1a89776f492d5342a1582 - ssdeep:
768:0gGzpDKpMyGEk58VR3OD/oe8ae51hRqJzQX480O/wOmAZCxcRsVPAIHAhAJ4:BGFmpNSyo80DO8xc2VPFHa+4 - TLSH:
T197328CF350B7ED4CB986DB03ADFA255A9489D708A033D624199C6B2CD0BC6BE3F50911 - Submitted as: 9325658.pdf
- File type: pdf · Size: 43731 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://sepikupi.weebly.com/uploads/1/3/0/7/130738949/kavawabukoweduz.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=kura%20bed%20instructions, https://cdn.shopify.com/s/files/1/0484/4948/7002/files/15813129024.pdf, https://cdn.shopify.com/s/files/1/0483/8693/2894/files/kozexamofiruladexinitogev.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=kura%20bed%20instructions
- https://cdn.shopify.com/s/files/1/0484/4948/7002/files/15813129024.pdf
- https://cdn.shopify.com/s/files/1/0483/8693/2894/files/kozexamofiruladexinitogev.pdf
- https://cdn.shopify.com/s/files/1/0266/7836/2298/files/numomijamozu.pdf
- https://cdn.shopify.com/s/files/1/0440/9245/7112/files/betatepuxo.pdf
- https://fuparududewon.weebly.com/uploads/1/3/1/8/131856041/c27324b56d05f.pdf
- https://sepikupi.weebly.com/uploads/1/3/0/7/130738949/kavawabukoweduz.pdf
- https://site-1037827.mozfiles.com/files/1037827/vifoxofakife.pdf
- https://site-1036697.mozfiles.com/files/1036697/88092501554.pdf
- https://site-1044256.mozfiles.com/files/1044256/89900353745.pdf
- https://site-1043559.mozfiles.com/files/1043559/xamafuzetabeni.pdf
- https://site-1044145.mozfiles.com/files/1044145/21147982057.pdf
- https://cdn.shopify.com/s/files/1/0498/7427/2408/files/30565706151.pdf
- https://cdn.shopify.com/s/files/1/0433/6828/4316/files/cas_project_ideas_in_quarantine.pdf
- https://cdn.shopify.com/s/files/1/0476/4460/6630/files/38651039577.pdf
- https://cdn.shopify.com/s/files/1/0433/3142/0314/files/abn_amro_mortgage_group_troy_michigan.pdf
- https://cdn.shopify.com/s/files/1/0437/4256/0407/files/93534648110.pdf
- https://uploads.strikinglycdn.com/files/2c60e233-72cd-43f8-be0f-9fb390bee4e0/xixulujosixatu.pdf
- https://uploads.strikinglycdn.com/files/5646e0ee-6c82-49c1-b935-4ad7358212bb/sanonebezune.pdf
- https://uploads.strikinglycdn.com/files/7877f22c-02a9-418f-a298-4b4cf4dfd3a4/vinusazefinobusiwufox.pdf
- https://uploads.strikinglycdn.com/files/c261f829-672b-42e2-b77d-aebf3295c44b/69797943294.pdf
- https://uploads.strikinglycdn.com/files/8a6a3a8b-104d-4f11-bcf9-36f76d68a33c/51702214962.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- fuparududewon.weebly.com
- sepikupi.weebly.com
- site-1037827.mozfiles.com
- site-1036697.mozfiles.com
- site-1044256.mozfiles.com
- site-1043559.mozfiles.com
- site-1044145.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report