MALICIOUS — 438702.pdf
MALICIOUS — 438702.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
dd5f3b9b140ef21bfe644593dc93868bfd4e50ea346b28a3ab0bb2ac4f20a914 - SHA-1:
5296715f4317dc4bfe3f6ae90c8da5e1080e0142 - MD5:
b62364e91b56f49ab7e08b7b2c3f19a3 - ssdeep:
768:qgGzpDgeyjXv0Ce8jiND+7vs+NYnkYz5yXsXL3xmMmShnKzXCDK41JuB1djHz5yV:3GF8eyrsCx+lr+NYnJzI+hnWCu4DwzTe - TLSH:
T1E6329EF350A7ED8C7BCBAB07D9A611996446D78C21328BB048C9777CC47CABD6E00A51 - Submitted as: 438702.pdf
- File type: pdf · Size: 47484 bytes
- Verdict: malicious (75/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://purolejomi.weebly.com/uploads/1/3/0/7/130776639/govikuwovirafat.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=2018%20mustang%20gt%20price, https://uploads.strikinglycdn.com/files/2d534ea7-bd07-462c-8fd7-072e386108e4/15052561740.pdf, https://uploads.strikinglycdn.com/files/9a513c7c-be73-49c9-b775-54e74418c58d/11169035061.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=2018%20mustang%20gt%20price
- https://uploads.strikinglycdn.com/files/2d534ea7-bd07-462c-8fd7-072e386108e4/15052561740.pdf
- https://uploads.strikinglycdn.com/files/9a513c7c-be73-49c9-b775-54e74418c58d/11169035061.pdf
- https://uploads.strikinglycdn.com/files/c056dd12-be53-4683-b116-88872a72158c/jikoripati.pdf
- https://uploads.strikinglycdn.com/files/36201af8-845d-43e8-a846-8597dde821c7/juwamozanakuva.pdf
- https://uploads.strikinglycdn.com/files/6287d6e3-e86c-4cb6-b50f-548fc2ee66b1/24767653898.pdf
- https://labajilawuja.weebly.com/uploads/1/3/1/4/131406369/gidanababuti.pdf
- https://kiseridebajesa.weebly.com/uploads/1/3/1/4/131408791/govubekafekipud.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/zakeme.pdf
- https://purolejomi.weebly.com/uploads/1/3/0/7/130776639/govikuwovirafat.pdf
- https://pumowurunumig.weebly.com/uploads/1/3/2/7/132740285/gurelutujerun.pdf
- https://uploads.strikinglycdn.com/files/cdd90776-845d-4c81-b474-99301939bd1e/60995804247.pdf
- https://uploads.strikinglycdn.com/files/07f3afec-7803-4739-bc65-211f702c9625/96116458684.pdf
- https://uploads.strikinglycdn.com/files/bbc017cd-0ee0-40d0-a991-58fed5a0ee18/mewiduzudafipi.pdf
- https://uploads.strikinglycdn.com/files/989ba276-3b72-4321-b831-c4f41ee98d68/tuzopas.pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/3883418899.pdf
- https://cdn.shopify.com/s/files/1/0429/5150/8131/files/st_benedict_prep_elementary_school.pdf
- https://uploads.strikinglycdn.com/files/a2bc86f3-d1b1-44f8-8afb-9f142bb30ed4/figure_of_speech_worksheets.pdf
- https://uploads.strikinglycdn.com/files/bc38968d-87d6-4d5a-9d87-d92f715d7f4f/48574598316.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- labajilawuja.weebly.com
- kiseridebajesa.weebly.com
- dimaxafazeza.weebly.com
- purolejomi.weebly.com
- pumowurunumig.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report