MALICIOUS — 41475884889.pdf
MALICIOUS — 41475884889.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fb160c63544ce597915b1b8763c8c5229f73e7738bc0ac7e9a9b9af97788b665 - SHA-1:
2e18ab1db70f7bd719582f4abd9d5db2f7490790 - MD5:
458ad68fda72bc15cd8829673f5f0717 - ssdeep:
768:5+gGzpDA7vNCf66yQhbRuVjTbqBVIVjzWkmeQt6XQA4JvJtD+4Sioyuq:pGFcpzUQd551at6V4JvJdIyuq - TLSH:
T1D3319FF351E3DD4D7A8AAB07ADAA005C628ACB8C703657A055C86B7DC4BC2FE1F04951 - Submitted as: 41475884889.pdf
- File type: pdf · Size: 42968 bytes
- Verdict: malicious (75/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/b982e4cc-b9ea-4630-9dcb-1cf30088ada8/ragozaka.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=strategic+management+theory+an+integrated+approach+12th+edition+pdf, https://uploads.strikinglycdn.com/files/72f4c365-fdf8-4672-8a7b-50e2834596ae/dixokejavawakeboxuzame.pdf, https://uploads.strikinglycdn.com/files/bba37c15-2ef7-47cb-993b-f07d792c75e6/15315841402.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=strategic+management+theory+an+integrated+approach+12th+edition+pdf
- https://uploads.strikinglycdn.com/files/72f4c365-fdf8-4672-8a7b-50e2834596ae/dixokejavawakeboxuzame.pdf
- https://uploads.strikinglycdn.com/files/bba37c15-2ef7-47cb-993b-f07d792c75e6/15315841402.pdf
- https://uploads.strikinglycdn.com/files/8f834f02-536c-48ac-90a7-654dcdf20408/tuxapajelegadi.pdf
- https://uploads.strikinglycdn.com/files/f0feab84-7855-4cac-a0ba-af481858bbc4/34608593273.pdf
- https://uploads.strikinglycdn.com/files/b982e4cc-b9ea-4630-9dcb-1cf30088ada8/ragozaka.pdf
- https://uploads.strikinglycdn.com/files/240abc32-6597-407f-9713-1f04c1570d3b/siluxowezobaxuribo.pdf
- https://cdn.shopify.com/s/files/1/0430/4463/4773/files/aprilia_mana_850_top_speed.pdf
- https://cdn.shopify.com/s/files/1/0482/7568/5531/files/fomofivomiporikojom.pdf
- https://cdn.shopify.com/s/files/1/0431/7115/2023/files/64955669171.pdf
- http://files.jasmanconstruction.com/uploads/1/3/2/6/132695813/777484.pdf
- http://jowam.maketucoastguard.com/uploads/1/3/1/8/131857631/kukanamajovomunuxil.pdf
- http://files.kadkahwinlovely.com/uploads/1/3/0/8/130874676/bedeb.pdf
- http://kewizobiv.annarbortreeservice.net/uploads/1/3/0/7/130775413/2173172.pdf
- http://wejofe.rmwle.org/uploads/1/3/1/4/131438523/16950.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- files.jasmanconstruction.com
- jowam.maketucoastguard.com
- files.kadkahwinlovely.com
- kewizobiv.annarbortreeservice.net
- wejofe.rmwle.org
- 2.fi
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report