MALICIOUS — gedetu.pdf
MALICIOUS — gedetu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0b177c6559f1129e56f25daadddf8715ce3e1b1698ffef4bd8343ad0300d3f67 - SHA-1:
ef7720efdbeb1f18e55a41f0ffa7f4dfa93b2c8b - MD5:
cf24d45c26172cf8baf67669c5e01ab3 - ssdeep:
1536:yGFApG9MJlVtviA8wriD+94/8sAxFrgkh:rFApLvtviAbODE4EZtj - TLSH:
T19C35AEF714D7EC4CBA8AAB13BCAB2529148DD78C6236D7A045CC272CD5AC5BD3E10A41 - Submitted as: gedetu.pdf
- File type: pdf · Size: 58387 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jawowigo.weebly.com/uploads/1/3/0/7/130774982/xovaragimogerem.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=fender%20performer%201000%20schematic, https://site-1036941.mozfiles.com/files/1036941/kifovujexokoxesakopif.pdf, https://site-1037221.mozfiles.com/files/1037221/bivuwikisomazapapexa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=fender%20performer%201000%20schematic
- https://site-1036941.mozfiles.com/files/1036941/kifovujexokoxesakopif.pdf
- https://site-1037221.mozfiles.com/files/1037221/bivuwikisomazapapexa.pdf
- https://site-1048481.mozfiles.com/files/1048481/28846824847.pdf
- https://site-1043330.mozfiles.com/files/1043330/podonanapiwufaluvexa.pdf
- https://site-1043802.mozfiles.com/files/1043802/jlpt_n5_grammar_book.pdf
- https://jawowigo.weebly.com/uploads/1/3/0/7/130774982/xovaragimogerem.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/bamudepekepa_setumazowido.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/kinufijozulof.pdf
- https://pofemazavuson.weebly.com/uploads/1/3/2/3/132303373/8148086.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/mukobuf.pdf
- https://uploads.strikinglycdn.com/files/52ae87c9-f1cc-4e58-b161-b125da7eaad4/48510526280.pdf
- https://uploads.strikinglycdn.com/files/a5cf6e27-1a3d-4d23-8e40-b63f19c64afa/dopukinuturemovubesodatuj.pdf
- https://uploads.strikinglycdn.com/files/0ef334dc-9ffe-4415-9b26-fb7f88b97f1b/73428043065.pdf
- https://uploads.strikinglycdn.com/files/5bc9067b-2fe9-4978-bfe4-beee3461a702/18929134543.pdf
- https://uploads.strikinglycdn.com/files/b7cfc1a7-36c3-45e9-a38a-63ee8b8dba8a/gawemud.pdf
- https://uploads.strikinglycdn.com/files/4be0566e-b935-44ca-9174-f6fb173e383b/vapegekizakiregimabota.pdf
- https://uploads.strikinglycdn.com/files/78aa8f4b-543d-403e-941f-48d720774d64/72329275446.pdf
- https://uploads.strikinglycdn.com/files/f039c00e-c23d-4bd7-84b9-d88306402367/11313440037.pdf
- https://cdn.shopify.com/s/files/1/0436/8800/1689/files/five_letter_words_starting_with_ei.pdf
- https://cdn.shopify.com/s/files/1/0434/1966/4540/files/british_white_cattle.pdf
- https://cdn.shopify.com/s/files/1/0481/0653/7111/files/79977851903.pdf
- https://cdn.shopify.com/s/files/1/0482/9007/0689/files/the_power_of_being_a_real_woman.pdf
- https://cdn-cms.f-static.net/uploads/4366982/normal_5f872bcbe573c.pdf
- https://cdn-cms.f-static.net/uploads/4367311/normal_5f87590c52218.pdf
Embedded domains
- cctraff.ru
- site-1036941.mozfiles.com
- site-1037221.mozfiles.com
- site-1048481.mozfiles.com
- site-1043330.mozfiles.com
- site-1043802.mozfiles.com
- jawowigo.weebly.com
- vuxozajuje.weebly.com
- pofemazavuson.weebly.com
- zoxuzuxebexot.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report