MALICIOUS — 6751379.pdf
MALICIOUS — 6751379.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
10ae2b7043614d31a35aea438ad2b30f6380424ecf0f40b8b40dfd1e7f2b72c8 - SHA-1:
46c4c4efebbeee95f9b94ab381e54a77c1404f77 - MD5:
7b729e2b0202ca23bac676965427cb71 - ssdeep:
1536:FGFRp/SYG5BGyrqNJPjxt9UQdMWi3b/Gx5df:YFRp6YVljLDdwm - TLSH:
T1B5338DF304D7DC8C7A866F13AFA754A96886874862319790548CFB3ECC7C9BD6E10921 - Submitted as: 6751379.pdf
- File type: pdf · Size: 51543 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/likanutavorolebonat.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=contoh%20soal%20aritmatika%20sosial%20pdf, https://kubupukadumu.weebly.com/uploads/1/3/1/3/131382740/tugutofanizijaw.pdf, https://pimupaxepa.weebly.com/uploads/1/3/1/8/131857198/fddd209288dbc.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=contoh%20soal%20aritmatika%20sosial%20pdf
- https://kubupukadumu.weebly.com/uploads/1/3/1/3/131382740/tugutofanizijaw.pdf
- https://pimupaxepa.weebly.com/uploads/1/3/1/8/131857198/fddd209288dbc.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/likanutavorolebonat.pdf
- https://lagukekejase.weebly.com/uploads/1/3/0/8/130815031/wusinaje_zeluze_fudakatulizix.pdf
- https://cdn-cms.f-static.net/uploads/4379220/normal_5f8a326bbdb29.pdf
- https://cdn-cms.f-static.net/uploads/4365563/normal_5f8717bc5aa04.pdf
- https://cdn-cms.f-static.net/uploads/4366319/normal_5f88ac0c18a7f.pdf
- https://cdn-cms.f-static.net/uploads/4367940/normal_5f8af1bb8a909.pdf
- https://cdn-cms.f-static.net/uploads/4365656/normal_5f870a7c1b3db.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/mikukinib.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/9232432.pdf
- https://gusumadanu.weebly.com/uploads/1/3/2/6/132695601/6894496.pdf
- https://uploads.strikinglycdn.com/files/a31d9293-45b7-4f44-8ac6-27f6358a4971/mufoguzabejipitolepepuzej.pdf
- https://uploads.strikinglycdn.com/files/3b2ad16f-7767-430a-988d-bbc60b9604cd/4011240053.pdf
- https://uploads.strikinglycdn.com/files/89302c64-6813-47e8-8930-fbe8eec8e625/44685622616.pdf
- https://uploads.strikinglycdn.com/files/e09f851a-52b9-414d-8837-f3b4ec91aaa7/zefamomugefilavo.pdf
- https://uploads.strikinglycdn.com/files/290e0267-f4c6-42a5-9c28-e28461c43652/5907836980.pdf
- https://uploads.strikinglycdn.com/files/331671cc-b8bb-4c35-be16-0b1bb1dee748/3588330361.pdf
- https://uploads.strikinglycdn.com/files/0ee92654-e512-4792-8ecc-a77e476bb4c4/47650008197.pdf
- https://uploads.strikinglycdn.com/files/1900bcc7-c5c6-4575-9c53-b8a7b30dde5c/kowalisob.pdf
- https://uploads.strikinglycdn.com/files/ad6f05f9-92fe-4161-b38f-32192442adc6/tanimijevebo.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/18ad995.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/dekegu.pdf
- https://jewajufigojoxi.weebly.com/uploads/1/3/1/4/131438211/repulefadedor-murew-gebujaboda.pdf
Embedded domains
- ggtraff.ru
- kubupukadumu.weebly.com
- pimupaxepa.weebly.com
- jakedekokobara.weebly.com
- lagukekejase.weebly.com
- cdn-cms.f-static.net
- keniwuki.weebly.com
- jawasolasazilem.weebly.com
- gusumadanu.weebly.com
- uploads.strikinglycdn.com
- dutitujazekap.weebly.com
- bedizegoresupa.weebly.com
- jewajufigojoxi.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report