MALICIOUS — 8104122.pdf
MALICIOUS — 8104122.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e2cbe079af840f1b2523e64cbb70304bf9d8849baf303d9a1c54982c84003fce - SHA-1:
c6befd66b4f20bb1d471188035fc6538ef4827be - MD5:
5538f9adb3358334b72384ac4bfc3b37 - ssdeep:
768:pgGzpDgpmBXcCO2dKBBH+8MZ9Hn/EuHVBW48EeYwSM87jG+aItura:KGFkpmj9/EuHVBW2eY7M8nGNIt2a - TLSH:
T12B32AEF360A7EE4C7A8A9B136EEA2069658AC3496033D7A044CC375DC47C5ED7E10961 - Submitted as: 8104122.pdf
- File type: pdf · Size: 45694 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/e27909d0be.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=pop%20rock%20and%20soul%20reader%20pdf, https://cdn-cms.f-static.net/uploads/4366018/normal_5f8712298f6d9.pdf, https://cdn-cms.f-static.net/uploads/4367311/normal_5f87583bb3be5.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=pop%20rock%20and%20soul%20reader%20pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f8712298f6d9.pdf
- https://cdn-cms.f-static.net/uploads/4367311/normal_5f87583bb3be5.pdf
- https://cdn-cms.f-static.net/uploads/4366327/normal_5f874be58efb4.pdf
- https://cdn-cms.f-static.net/uploads/4366365/normal_5f874b8b4a528.pdf
- https://cdn-cms.f-static.net/uploads/4366371/normal_5f87432f4db13.pdf
- https://nikokabiliru.weebly.com/uploads/1/3/1/4/131409463/ec649c376a6cdbb.pdf
- https://misutinulil.weebly.com/uploads/1/3/1/4/131407711/d8afce88862.pdf
- https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/e27909d0be.pdf
- https://uploads.strikinglycdn.com/files/ddcad09e-5a18-4588-adc0-0071cf5eb19f/85292554813.pdf
- https://uploads.strikinglycdn.com/files/f75ba213-7d58-4afa-a91b-8c2c98bbd818/13306144642.pdf
- https://site-1038505.mozfiles.com/files/1038505/17668803.pdf
- https://site-1043329.mozfiles.com/files/1043329/55044643177.pdf
- https://uploads.strikinglycdn.com/files/c60211ce-2505-4135-b62b-3499802954b4/dogoreworip.pdf
- https://uploads.strikinglycdn.com/files/3bb5b34c-5e77-4964-aac5-0832dc8bdcc0/lepadidedowoku.pdf
- https://uploads.strikinglycdn.com/files/c0b05013-fea8-4e88-ba66-bb7b5a81f1ec/79565906946.pdf
- https://cdn-cms.f-static.net/uploads/4368237/normal_5f87fa6d7a004.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f86fef3ce6a8.pdf
- https://cdn-cms.f-static.net/uploads/4366032/normal_5f876328e76d3.pdf
- https://cdn-cms.f-static.net/uploads/4366004/normal_5f87eb92decab.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- nikokabiliru.weebly.com
- misutinulil.weebly.com
- gevafitasib.weebly.com
- uploads.strikinglycdn.com
- site-1038505.mozfiles.com
- site-1043329.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report