MALICIOUS — a18b68879d139d2.pdf
MALICIOUS — a18b68879d139d2.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ff438c94d3e91469784f7bc292953ca6f028da3f112be0bc7ad3993bd8389c31 - SHA-1:
d64e4570f54075023b78c0c832f49e7de014efc6 - MD5:
b4e90dc6243fee31533a51e62de7bb0b - ssdeep:
768:FgGzpD7pDxR8fRkxrFiK1W5zLuFY36gDiRHUj/66B0SIsRrN0hps:WGFnpNqPzLue36jRHUj/7BdIsT0hps - TLSH:
T17B307DF3509BED4C7A8A9B039CEB155A608AC38C6177A790548C7B7DD0BC6AD7E00861 - Submitted as: a18b68879d139d2.pdf
- File type: pdf · Size: 38767 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/xojajuv-mitegejitokuxig.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=how%20to%20download%20java%20without%20adminis, https://uploads.strikinglycdn.com/files/a7895000-d544-4c93-9042-54b3b672ab57/kunupuritojiful.pdf, https://uploads.strikinglycdn.com/files/f800c973-5794-4f5a-a009-a0829c4e2e65/2019050304.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=how%20to%20download%20java%20without%20adminis
- https://uploads.strikinglycdn.com/files/a7895000-d544-4c93-9042-54b3b672ab57/kunupuritojiful.pdf
- https://uploads.strikinglycdn.com/files/f800c973-5794-4f5a-a009-a0829c4e2e65/2019050304.pdf
- https://uploads.strikinglycdn.com/files/7540c886-6194-4b56-aea2-0cd74ad35139/64726562471.pdf
- https://ganulexotugoris.weebly.com/uploads/1/3/1/1/131164012/zejuma_bonolozomagu.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/xojajuv-mitegejitokuxig.pdf
- https://zeginuvo.weebly.com/uploads/1/3/0/7/130775519/1903210.pdf
- https://xuwuperozaposa.weebly.com/uploads/1/3/2/3/132303395/dd7811.pdf
- https://cdn.shopify.com/s/files/1/0497/3677/7877/files/software_engineering_notes_for_msc.pdf
- https://cdn.shopify.com/s/files/1/0431/8366/9412/files/fejazupijadulabotisop.pdf
- https://cdn.shopify.com/s/files/1/0499/6120/5924/files/z_transform_table_from_s_domain.pdf
- https://cdn.shopify.com/s/files/1/0266/9559/8272/files/the_essential_writings_of_mahatma_gandhi.pdf
- https://cdn.shopify.com/s/files/1/0503/4639/3758/files/asus_router_openvpn_android.pdf
- https://cdn.shopify.com/s/files/1/0498/8593/7818/files/wekulutafirikibunuzox.pdf
- https://cdn.shopify.com/s/files/1/0481/6997/5965/files/surry_county_clerk_of_court.pdf
- https://cdn.shopify.com/s/files/1/0434/2461/2509/files/pulau_ubin_travel_guide.pdf
- https://site-1044301.mozfiles.com/files/1044301/hsbc_premier_travel_insurance_policy.pdf
- https://site-1037166.mozfiles.com/files/1037166/wukiranejidosikunod.pdf
- https://site-1040346.mozfiles.com/files/1040346/gadunuzesokudujepuje.pdf
- https://site-1043479.mozfiles.com/files/1043479/kixarup.pdf
- https://site-1043406.mozfiles.com/files/1043406/wibuge.pdf
- https://site-1044026.mozfiles.com/files/1044026/raxevasujukifapefepis.pdf
- https://site-1043564.mozfiles.com/files/1043564/41612560401.pdf
- https://site-1036862.mozfiles.com/files/1036862/nufefa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- ganulexotugoris.weebly.com
- gimejexoxixaza.weebly.com
- zeginuvo.weebly.com
- xuwuperozaposa.weebly.com
- cdn.shopify.com
- site-1044301.mozfiles.com
- site-1037166.mozfiles.com
- site-1040346.mozfiles.com
- site-1043479.mozfiles.com
- site-1043406.mozfiles.com
- site-1044026.mozfiles.com
- site-1043564.mozfiles.com
- site-1036862.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report