MALICIOUS — c9686fff3a9e.pdf
MALICIOUS — c9686fff3a9e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c6faadf948dfdd39938a2f4ac225b28c034afb5aaa319cbf442fc221858b2c92 - SHA-1:
da8aa89797eafb98b4d165d55e203a1eba0ee9de - MD5:
f5b1aa4a0dacb9cf1cf4e86c81e3a82c - ssdeep:
1536:KGFzpeJ9KLhLlvvfaVkQPMMZbAu5Gzxs2z4mFviBjiUVd+Pf:zFzpeJY73fZqNtAuoz54mVi5iwd4 - TLSH:
T16835BEF31087EE8DA547EF43A9AB202E618AC78910769760598C7B5CC1BC3BE3F10651 - Submitted as: c9686fff3a9e.pdf
- File type: pdf · Size: 62750 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/7fb67504-4cbc-4ace-9d22-8be47fdacd60/zukep.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=examen%204%20bimestre%206%20grado, https://uploads.strikinglycdn.com/files/7fb67504-4cbc-4ace-9d22-8be47fdacd60/zukep.pdf, https://uploads.strikinglycdn.com/files/5164988d-fc18-42ac-9b39-19f1c0e9d6aa/96238240178.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=examen%204%20bimestre%206%20grado
- https://uploads.strikinglycdn.com/files/7fb67504-4cbc-4ace-9d22-8be47fdacd60/zukep.pdf
- https://uploads.strikinglycdn.com/files/5164988d-fc18-42ac-9b39-19f1c0e9d6aa/96238240178.pdf
- https://uploads.strikinglycdn.com/files/9c0262ed-dd5e-4b55-a82f-2cb317a14afc/vanogidamudij.pdf
- https://uploads.strikinglycdn.com/files/2e7c3a4d-3875-4f6d-baeb-3e8adca8e1ea/votilegebedivezike.pdf
- https://uploads.strikinglycdn.com/files/f2d2afb1-7081-43fa-8feb-fe75a88b4ed7/79808076542.pdf
- https://cdn.shopify.com/s/files/1/0438/4161/8082/files/where_the_red_fern_grows_questions_and_answers.pdf
- https://cdn.shopify.com/s/files/1/0486/6503/4902/files/85376051013.pdf
- https://cdn.shopify.com/s/files/1/0476/7934/0710/files/24159044841.pdf
- https://cdn.shopify.com/s/files/1/0433/2801/2456/files/2020_superduty_high_idle_features.pdf
- https://cdn.shopify.com/s/files/1/0430/1275/1523/files/neon_rope_lights_for_sale.pdf
- https://cdn.shopify.com/s/files/1/0502/7800/6966/files/79470057763.pdf
- https://cdn.shopify.com/s/files/1/0437/0667/9464/files/inteligencia_emocional_2.0_travis_bradberry_descargar_gratis.pdf
- https://cdn.shopify.com/s/files/1/0498/7227/3566/files/jersey_city_teacher_salary_guide.pdf
- https://site-1040881.mozfiles.com/files/1040881/percent_proportion_problems_worksheet.pdf
- https://site-1038299.mozfiles.com/files/1038299/84374790194.pdf
- https://cdn.shopify.com/s/files/1/0431/3032/3095/files/19212672222.pdf
- https://cdn.shopify.com/s/files/1/0428/9783/4143/files/89398022290.pdf
- https://cdn.shopify.com/s/files/1/0431/4605/1744/files/jobagiw.pdf
- https://cdn.shopify.com/s/files/1/0431/5847/0807/files/introduction_letter_to_parents_from_new_teacher.pdf
- https://cdn.shopify.com/s/files/1/0482/7221/2130/files/8_ball_rack_order.pdf
- https://cdn.shopify.com/s/files/1/0484/3716/6230/files/lemetaxodovazuned.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1040881.mozfiles.com
- site-1038299.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report