MALICIOUS — 2446307.pdf
MALICIOUS — 2446307.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d1144a34d6088324696d7fac3d5d1c53630a152e903789d2c98f7452738eb2c3 - SHA-1:
5c0cf8c0d51153ef93fa1eecbebc176fb0621279 - MD5:
4a4240eb3df9fdb5c95e6693b1114832 - ssdeep:
768:kgGzpDEpaY8+sYtGElIYQxj0zGwsT/jkjB5XZREFE64Ns:RGF4p90GzxQbkt5JWFEzs - TLSH:
T1F7318CF30493DD8C7A8BAB83ADB7149A6185C388A137D7A055887B6DC4BC5ECBF01560 - Submitted as: 2446307.pdf
- File type: pdf · Size: 40092 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/godekux.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=canal%20starz%20en%20vivo, https://xazapadikud.weebly.com/uploads/1/3/1/8/131871762/1eb9c2e.pdf, https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/godekux.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=canal%20starz%20en%20vivo
- https://xazapadikud.weebly.com/uploads/1/3/1/8/131871762/1eb9c2e.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/godekux.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/7849bd296.pdf
- https://tekegalesi.weebly.com/uploads/1/3/0/7/130740489/wujelagovawub.pdf
- https://dagigokes.weebly.com/uploads/1/3/0/7/130739756/pewakijefaru_lavikefoled_rinenebot_zipulom.pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f872bf3d7bfe.pdf
- https://site-1039795.mozfiles.com/files/1039795/zimuvopojajekule.pdf
- https://site-1048572.mozfiles.com/files/1048572/8193219850.pdf
- https://cdn.shopify.com/s/files/1/0437/7378/8321/files/to_selena_with_love_download.pdf
- https://cdn.shopify.com/s/files/1/0434/4935/2349/files/46674951109.pdf
- https://cdn.shopify.com/s/files/1/0498/6178/7805/files/22975481109.pdf
- https://cdn.shopify.com/s/files/1/0437/4446/0951/files/vejawopafit.pdf
- https://cdn.shopify.com/s/files/1/0495/6569/6152/files/4_in_goal_2016.pdf
- https://cdn.shopify.com/s/files/1/0457/3783/6710/files/85904404000.pdf
- https://uploads.strikinglycdn.com/files/00e9ccdc-eb22-4cbd-b299-2546e2585b6d/lolodifiluzaxamisujase.pdf
- https://uploads.strikinglycdn.com/files/f48963a6-4623-424a-8656-add39eb783e0/22637269393.pdf
- https://uploads.strikinglycdn.com/files/6dbf648a-c427-4588-b41b-9ad596e12412/68168952483.pdf
- https://uploads.strikinglycdn.com/files/932abbb4-26ed-4159-b829-145f2b63d04a/firobetegirol.pdf
- https://uploads.strikinglycdn.com/files/676f847f-29a4-4fcc-a7f4-fbf97dc9eb99/tefazajelimibitalagagaded.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- xazapadikud.weebly.com
- jakedekokobara.weebly.com
- guwomenod.weebly.com
- tekegalesi.weebly.com
- dagigokes.weebly.com
- cdn-cms.f-static.net
- site-1039795.mozfiles.com
- site-1048572.mozfiles.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report