MALICIOUS — 3e352.pdf
MALICIOUS — 3e352.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 1 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
09788a8bddb6dca1df5100f97f240203374f10aa0d07604d20f44906bea7760e - SHA-1:
7e9f497be626a81e5703ba1495852b5e556c397a - MD5:
2ba23e58cd07f2b14051723c0f68d9d2 - ssdeep:
768:IgGzpDjpiV6PtO/hEzs3thATVqFALoqjwY:FGF3pw9OTVIAZjwY - TLSH:
T1D1305DF31097ED8C3A8B9F479EA7159E6586C78DA1369760048C7B2CC47C6ED2F00A25 - Submitted as: 3e352.pdf
- File type: pdf · Size: 38549 bytes
- Verdict: malicious (71/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/jibigamefomoni.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=bat%20box%20san%20pedro, https://sakuvida.weebly.com/uploads/1/3/0/7/130775714/cbb0ca98c903.pdf, https://sokuvotaboraj.weebly.com/uploads/1/3/0/7/130776263/metifefosamusotuji.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=bat%20box%20san%20pedro
- https://sakuvida.weebly.com/uploads/1/3/0/7/130775714/cbb0ca98c903.pdf
- https://sokuvotaboraj.weebly.com/uploads/1/3/0/7/130776263/metifefosamusotuji.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/jibigamefomoni.pdf
- https://nogafuku.weebly.com/uploads/1/3/2/8/132815296/purepujati.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/1a27643b41869.pdf
- https://uploads.strikinglycdn.com/files/a5ed78b2-8e5f-40ac-ad21-1ca71cfec188/bivapafapa.pdf
- https://uploads.strikinglycdn.com/files/4103a85b-e35f-4b66-951c-ef708a4fd0a3/pudupimogir.pdf
- https://zosupexaduj.weebly.com/uploads/1/3/0/7/130738593/zirisavinu_wonuxuwuke_lotanumotirob.pdf
- https://talapilodegopez.weebly.com/uploads/1/3/0/9/130969507/8b2e5e74.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/f9007.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/7c6cd08902ca5d6.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/dozafawegikuxoto.pdf
- https://cdn-cms.f-static.net/uploads/4366408/normal_5f8746db78cb8.pdf
- https://cdn-cms.f-static.net/uploads/4366366/normal_5f8729fbd939a.pdf
- https://cdn-cms.f-static.net/uploads/4369802/normal_5f88998760592.pdf
- https://cdn-cms.f-static.net/uploads/4366043/normal_5f87c68594bbc.pdf
- https://cdn-cms.f-static.net/uploads/4369932/normal_5f8cea8b3dca3.pdf
- https://xuvakaxatal.weebly.com/uploads/1/3/1/0/131070170/d29993308.pdf
- https://bizumoku.weebly.com/uploads/1/3/2/6/132681494/746383.pdf
- https://runebipunozup.weebly.com/uploads/1/3/1/4/131406604/41c70f74b38.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/1302795.pdf
- https://rutaluxunenore.weebly.com/uploads/1/3/0/7/130740368/3eae1cee9706f5.pdf
- https://rokolumer.weebly.com/uploads/1/3/0/9/130969153/a47c14fb2.pdf
- https://senobatupubem.weebly.com/uploads/1/3/1/4/131437889/lakumilevajegik.pdf
Embedded domains
- gettraff.ru
- sakuvida.weebly.com
- sokuvotaboraj.weebly.com
- fijojonibiw.weebly.com
- nogafuku.weebly.com
- zoxuzuxebexot.weebly.com
- uploads.strikinglycdn.com
- zosupexaduj.weebly.com
- talapilodegopez.weebly.com
- dutitujazekap.weebly.com
- jufaxexave.weebly.com
- vuxozajuje.weebly.com
- cdn-cms.f-static.net
- xuvakaxatal.weebly.com
- bizumoku.weebly.com
- runebipunozup.weebly.com
- jatorogerujew.weebly.com
- rutaluxunenore.weebly.com
- rokolumer.weebly.com
- senobatupubem.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report