MALICIOUS — 4457489.pdf
MALICIOUS — 4457489.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c9d0d6b0885ff0cad7eac28915e5b34f7ee1af6cb3f6097dd8edb6a76180479c - SHA-1:
9f756a094ec349519dc0df2f311b908a572768cf - MD5:
d3756b23ba9619bda70e0a26ca61eee8 - ssdeep:
1536:RGFo5xeaqo0GfSEAQzh1tGkvv7Cgd8vZWvqPI27WkixU5Lmiy07dZDy:0Fovv0Gfxt2gDmviqPnB5LmP07d8 - TLSH:
T15438C0F34093FD4E7E4B9F97ADAA252AB085CB887121E670549C7A6CC57866D3F40E00 - Submitted as: 4457489.pdf
- File type: pdf · Size: 81477 bytes
- Verdict: malicious (75/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jiwepurojal.weebly.com/uploads/1/3/0/7/130775762/lazejiwe.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=%D8%AA%D8%AD%D9%85%D9%8A%D9%84%20%D9%83%D8%AA%D8%A8%20%D8%B9%D9%84%D9%85%D9%8A%D8%A9%20%D9%85%D8%AA%D8%B1%D8%AC%D9%85%D8%A9%20pdf, https://cdn.shopify.com/s/files/1/0482/2620/5848/files/cpm_homework_geometry_answers.pdf, https://cdn.shopify.com/s/files/1/0496/0698/3829/files/android_app_development_sample_projects.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=%D8%AA%D8%AD%D9%85%D9%8A%D9%84%20%D9%83%D8%AA%D8%A8%20%D8%B9%D9%84%D9%85%D9%8A%D8%A9%20%D9%85%D8%AA%D8%B1%D8%AC%D9%85%D8%A9%20pdf
- https://cdn.shopify.com/s/files/1/0482/2620/5848/files/cpm_homework_geometry_answers.pdf
- https://cdn.shopify.com/s/files/1/0496/0698/3829/files/android_app_development_sample_projects.pdf
- https://cdn.shopify.com/s/files/1/0503/6235/1803/files/durgesh_nandini_in_bengali.pdf
- https://cdn.shopify.com/s/files/1/0266/8327/7491/files/ios_design_guidelines_font_size.pdf
- https://jiwepurojal.weebly.com/uploads/1/3/0/7/130775762/lazejiwe.pdf
- https://juporolo.weebly.com/uploads/1/3/1/3/131380745/fuvag.pdf
- https://lififotepul.weebly.com/uploads/1/3/4/3/134339298/6118641.pdf
- https://cdn-cms.f-static.net/uploads/4378382/normal_5f937b0fed915.pdf
- https://cdn-cms.f-static.net/uploads/4365580/normal_5f8b236d7bba1.pdf
- https://cdn-cms.f-static.net/uploads/4368238/normal_5f89b33c01a4f.pdf
- https://cdn-cms.f-static.net/uploads/4368748/normal_5f8f4b00e5824.pdf
- https://s3.amazonaws.com/gupuso/4684175396.pdf
- https://s3.amazonaws.com/ligole/gutimor.pdf
- https://s3.amazonaws.com/zuxadol/kexosef.pdf
- https://cdn.shopify.com/s/files/1/0496/1189/9044/files/48515956565.pdf
- https://cdn.shopify.com/s/files/1/0498/8315/2540/files/jewirabolupiputamofegi.pdf
- https://cdn.shopify.com/s/files/1/0433/7182/3262/files/acs_biomaterials_science__engineering_author_guidelines.pdf
- https://cdn.shopify.com/s/files/1/0482/7847/0817/files/oregon_ducks_uniforms_vs_auburn.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- jiwepurojal.weebly.com
- juporolo.weebly.com
- lififotepul.weebly.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report