MALICIOUS — 43998784500.pdf
MALICIOUS — 43998784500.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c954b41a7e148b2470e309b29764b87611e210bcae0670f6b607aeeff5a664a8 - SHA-1:
d086084667f9ab6d148af6c55e6a1143364b0929 - MD5:
9fff76708be1c02b578542e89edfd1b3 - ssdeep:
768:YgGzpDQ5xSI1zyFLGr2FQGF9kwRAcOW4lAMEFGrioXsU6JfNilLxw:1GFs5xj2ar2a49VLOtREFG14JVilLxw - TLSH:
T1E8329DF350A3ED4C398BAB879EE6049D615A978C2122976014D83B3DC8BC7FD6F11A50 - Submitted as: 43998784500.pdf
- File type: pdf · Size: 46516 bytes
- Verdict: malicious (75/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/0fece531-3fef-4b6f-accc-c197ff95acee/fotigozenujawemowafaf.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=variedades+de+cafe+en+guatemala+pdf, https://uploads.strikinglycdn.com/files/4437a217-a762-401e-8989-852505fad348/50215539568.pdf, https://uploads.strikinglycdn.com/files/f727f262-ca3b-4c40-92a0-9b470813ac27/togafitufa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=variedades+de+cafe+en+guatemala+pdf
- https://uploads.strikinglycdn.com/files/4437a217-a762-401e-8989-852505fad348/50215539568.pdf
- https://uploads.strikinglycdn.com/files/f727f262-ca3b-4c40-92a0-9b470813ac27/togafitufa.pdf
- https://uploads.strikinglycdn.com/files/0fece531-3fef-4b6f-accc-c197ff95acee/fotigozenujawemowafaf.pdf
- https://uploads.strikinglycdn.com/files/3de808ef-5f2e-443d-bc22-c07dbc224ac5/dozuzowalomuri.pdf
- https://uploads.strikinglycdn.com/files/4e0f04c3-ec2e-449d-a954-b21ed47111d6/10797040378.pdf
- http://risirefi.tohgallery.com/uploads/1/3/0/8/130814328/lijog.pdf
- http://vujiweta.nextlevelbizgrowth.com/uploads/1/3/1/4/131411688/faaadcbe.pdf
- http://files.cohicatravel.com/uploads/1/3/1/4/131407315/7593676.pdf
- https://uploads.strikinglycdn.com/files/d506b3f3-ddd7-4182-8cfa-8f6b65673f5a/folaniroxusunos.pdf
- https://uploads.strikinglycdn.com/files/26d33819-b9e1-4e27-9422-4a15ed57e2eb/lifigipizujidadid.pdf
- https://uploads.strikinglycdn.com/files/c4b7b7ec-7f67-4542-8d00-a50cf663b4e9/43859052963.pdf
- https://uploads.strikinglycdn.com/files/aa172da4-e377-4ce0-9c24-f56933dc7905/zuxilorukone.pdf
- https://uploads.strikinglycdn.com/files/be48e1e4-0f95-430c-8787-19b12c8efeab/zaziga.pdf
- https://cdn.shopify.com/s/files/1/0429/7120/1699/files/opal_creek_hike_map.pdf
- https://cdn.shopify.com/s/files/1/0485/0162/0898/files/kill_phil_poker_book.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- risirefi.tohgallery.com
- vujiweta.nextlevelbizgrowth.com
- files.cohicatravel.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report