MALICIOUS — 4869460.pdf
MALICIOUS — 4869460.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fc53f64c44325baa9f0a8f8f87a411f16c226164b931202732172719ce302ad6 - SHA-1:
0310f27c44481fb61eab2d2fa44b70ad440cda68 - MD5:
e76fb5e3fb86ff2489dfbad176636202 - ssdeep:
768:kgGzpDnp+L/BM30EpN3apGhTlYzm0l/8Ow6h+6e7t7bEGaXYhd80M7dR7:RGFrpAolI88QD5E1Ihd80qdR7 - TLSH:
T10E32AEF31497EC8C7A87AB036CAB1869554ECA886232E72041DD767CC5BC6BD7F00960 - Submitted as: 4869460.pdf
- File type: pdf · Size: 44735 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://gukepofefefika.weebly.com/uploads/1/3/1/4/131437977/8957516.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=tsuki%20adventure%20guide, https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/risunave-wobugar-bepavajug.pdf, https://fimosezit.weebly.com/uploads/1/3/0/7/130775491/befivawatokezikub.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=tsuki%20adventure%20guide
- https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/risunave-wobugar-bepavajug.pdf
- https://fimosezit.weebly.com/uploads/1/3/0/7/130775491/befivawatokezikub.pdf
- https://gukepofefefika.weebly.com/uploads/1/3/1/4/131437977/8957516.pdf
- https://sepikupi.weebly.com/uploads/1/3/0/7/130738949/tijame_wiwevuba_morupuxetenob_darolel.pdf
- https://zoveponezewuda.weebly.com/uploads/1/3/0/7/130738822/befofobojixubut.pdf
- https://cdn.shopify.com/s/files/1/0432/5097/4888/files/am_consolidated_high_school_yearbook.pdf
- https://cdn.shopify.com/s/files/1/0429/3669/6995/files/zunaxitezutom.pdf
- https://cdn.shopify.com/s/files/1/0434/2435/0375/files/zawetasegavejewarubokava.pdf
- https://cdn.shopify.com/s/files/1/0497/3900/6113/files/android_sdk_avd_manager_location.pdf
- https://uploads.strikinglycdn.com/files/39be5036-a742-4313-92b2-25d8e6c916b3/varutebofaw.pdf
- https://uploads.strikinglycdn.com/files/a29e4ec7-31a3-48b9-800f-352b61b28838/77717815072.pdf
- https://uploads.strikinglycdn.com/files/a74c7713-8a05-42b4-8255-3e1db2814fa7/rebasusuk.pdf
- https://cdn.shopify.com/s/files/1/0482/0605/3533/files/lejevidepapajukipajo.pdf
- https://cdn.shopify.com/s/files/1/0483/3473/3465/files/alexander_and_roberts_galapagos.pdf
- https://cdn.shopify.com/s/files/1/0493/6489/3855/files/it-205_instructions_2017.pdf
- https://cdn.shopify.com/s/files/1/0479/4309/0332/files/cannot_mount_database_in_exclusive_mode.pdf
- https://cdn-cms.f-static.net/uploads/4368485/normal_5f87c05053b59.pdf
- https://cdn-cms.f-static.net/uploads/4366339/normal_5f87a0efbc1ee.pdf
- https://cdn.shopify.com/s/files/1/0481/7882/3317/files/real_estate_investment_prospectus.pdf
- https://cdn.shopify.com/s/files/1/0491/7094/0070/files/philips_avent_sterilizer_user_manual.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- megadezatesaram.weebly.com
- fimosezit.weebly.com
- gukepofefefika.weebly.com
- sepikupi.weebly.com
- zoveponezewuda.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report