MALICIOUS — 7219382.pdf
MALICIOUS — 7219382.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c846c9eff600d3a6fa704195bdf9a43f2982e399d21da645bba0365d19911e6b - SHA-1:
8ff879278b7515730159a9f56decf30865d29eae - MD5:
c51b41fb5f0de8f6271ff2120f32291d - ssdeep:
6144:5fTtGvRB1kYhFgytrV0C23szrvfYeaBpfCgm:9p81hRVn23mr3YHBpfS - TLSH:
T1054379F3F1829E6814D95A0A7A9208F93DC4C54C31A29BB02F9527DFB5DB6B91B30431 - Submitted as: 7219382.pdf
- File type: pdf · Size: 227800 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/4918653.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=grammar%20practice%20for%20upper%20intermediate%20students%20elaine%20walker%20pdf, https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/4918653.pdf, https://suzokixuvajix.weebly.com/uploads/1/3/0/7/130776208/285958.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=grammar%20practice%20for%20upper%20intermediate%20students%20elaine%20walker%20pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/4918653.pdf
- https://suzokixuvajix.weebly.com/uploads/1/3/0/7/130776208/285958.pdf
- https://wevuviwujito.weebly.com/uploads/1/3/1/6/131636984/705ec1e3dc.pdf
- https://fakimodixoto.weebly.com/uploads/1/3/0/7/130739088/lizel.pdf
- https://walijogopabo.weebly.com/uploads/1/3/0/7/130776167/punitetiva.pdf
- https://cdn-cms.f-static.net/uploads/4369769/normal_5f91e36b813b3.pdf
- https://cdn-cms.f-static.net/uploads/4382412/normal_5f8fa4a6a2fbc.pdf
- https://cdn-cms.f-static.net/uploads/4365575/normal_5f87e7d845840.pdf
- https://cdn-cms.f-static.net/uploads/4365575/normal_5f870ce048ea5.pdf
- https://uploads.strikinglycdn.com/files/ee8eda22-4a7f-4a11-9bdd-9656859756f0/rudaxelebaro.pdf
- https://uploads.strikinglycdn.com/files/54a89876-20a2-4d96-853a-b6f72553f109/tafegil.pdf
- https://uploads.strikinglycdn.com/files/45a2b125-1282-4540-bb94-0014e7cda505/98501867394.pdf
- https://uploads.strikinglycdn.com/files/137d5044-d9bd-497f-9215-f942bd298f2e/xodamilafupinive.pdf
- https://uploads.strikinglycdn.com/files/a2ce06db-d865-45cf-bc2a-d0b795e6d308/kritika_the_white_knights_pet_guide.pdf
- https://s3.amazonaws.com/mipeboro/wifisagekekofoworegemeb.pdf
- https://s3.amazonaws.com/henghuili-files/bogez.pdf
- https://s3.amazonaws.com/susopuzupure/philippine_articles_about_academic_performance.pdf
- https://s3.amazonaws.com/sugaguxagu/xupikup.pdf
- https://uploads.strikinglycdn.com/files/3678bec1-111a-403a-9488-e0ac4714647c/piziriluno.pdf
- https://uploads.strikinglycdn.com/files/a7f1d913-f4b2-496f-89a0-b2c7eb48bcdb/32427803977.pdf
- https://uploads.strikinglycdn.com/files/53696820-4a94-4270-b4d8-960669968803/the_birth_of_capitalism_a_21st_century_perspective.pdf
- https://uploads.strikinglycdn.com/files/362cc1e0-23bb-4dff-afcd-6e00d4cb850c/sononilawolafuretegugew.pdf
- https://uploads.strikinglycdn.com/files/07af7bce-f039-4267-ac45-08ab14507994/42028437216.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- jakedekokobara.weebly.com
- suzokixuvajix.weebly.com
- wevuviwujito.weebly.com
- fakimodixoto.weebly.com
- walijogopabo.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report