MALICIOUS — 8f49e2c64866c7.pdf
MALICIOUS — 8f49e2c64866c7.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
02bca8d7c2201e86207224f3d8ec7a96fb4b1f9dac44b778d25bf6befbc8efdc - SHA-1:
a7c1979d101838c342cf5a1673b6c4713f3c10c8 - MD5:
aea764c006983d3e84d28b2a18f619ce - ssdeep:
768:XgGzpDIpQ4cNiqiUqdQfxB/dt8vGD3GBbLHerD4bF8AWlp2U2g7nwY1usFs:wGFspQ3QG7KjGkmAon2g7nLusFs - TLSH:
T1F8319DF340A3EC8C768F6B03ADEA1159618AD78D50329A9104CC772CE5BCAFC7E11961 - Submitted as: 8f49e2c64866c7.pdf
- File type: pdf · Size: 40196 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/32e063a95e.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=wortschatz%20c2%20deutsch%20liste%20pdf, https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/32e063a95e.pdf, https://lesofetu.weebly.com/uploads/1/3/1/3/131378838/ed66499a7cc.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=wortschatz%20c2%20deutsch%20liste%20pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/32e063a95e.pdf
- https://lesofetu.weebly.com/uploads/1/3/1/3/131378838/ed66499a7cc.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/3079835.pdf
- https://lesajevix.weebly.com/uploads/1/3/4/3/134318042/8818382.pdf
- https://tebamebameden.weebly.com/uploads/1/3/3/9/133997375/2060604.pdf
- https://cdn-cms.f-static.net/uploads/4368467/normal_5f8a9dce07664.pdf
- https://cdn-cms.f-static.net/uploads/4379610/normal_5f8e5c99c56a8.pdf
- https://cdn-cms.f-static.net/uploads/4373522/normal_5f8c031287218.pdf
- https://cdn.shopify.com/s/files/1/0431/5480/0796/files/9273523769.pdf
- https://cdn.shopify.com/s/files/1/0484/6603/4849/files/gta_v_mobile_apk.pdf
- https://cdn.shopify.com/s/files/1/0502/4746/7163/files/free_poultry_business_plan.pdf
- https://uploads.strikinglycdn.com/files/9a4d8d82-fe39-4b26-b39f-32eb2b7a98fc/sawipesegaponikelanolewo.pdf
- https://uploads.strikinglycdn.com/files/f3b03fea-504d-437e-85a3-33cfbf4bf9b1/sajudakowikebonagunod.pdf
- https://uploads.strikinglycdn.com/files/c69952b4-bbbb-44e8-8413-c20f1b09ed0c/85587689799.pdf
- https://uploads.strikinglycdn.com/files/a69de6fd-edf5-423d-8424-7a3c520fed89/93250354984.pdf
- https://cdn.shopify.com/s/files/1/0462/3876/1109/files/download_webtoon_apk_free.pdf
- https://cdn.shopify.com/s/files/1/0483/8460/6359/files/nutid_double_oven_manual.pdf
- https://cdn.shopify.com/s/files/1/0499/6543/2985/files/waze_cannot_connect_to_gps_android.pdf
- https://cdn.shopify.com/s/files/1/0266/9153/5020/files/63715962366.pdf
- https://cdn.shopify.com/s/files/1/0483/6343/8243/files/gegexegisudorufewutep.pdf
- https://deutschschnellundeinfachlernen.wordpress.com/Alle
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- keniwuki.weebly.com
- lesofetu.weebly.com
- zoxuzuxebexot.weebly.com
- lesajevix.weebly.com
- tebamebameden.weebly.com
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- deutschschnellundeinfachlernen.wordpress.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report