MALICIOUS — 90968687504.pdf
MALICIOUS — 90968687504.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
14f5cff9c9d534696b3fd971a11276d153f56131108c21191ce9478e932f3887 - SHA-1:
0619eb91ef31f4a5c20e1e1345ce77dde9ca41dd - MD5:
74c103fdd1d419b55673c33883c85d12 - ssdeep:
1536:tGF3Lk/H+i4CFykHZREDj138K+yKWSBZxu:wF3LYWCFyCREf1zkB+ - TLSH:
T1DC348EF310A7DD8D3A9BAB13B9A71059618ACB8C7136975085C87B2CE4BC6BD7E10C50 - Submitted as: 90968687504.pdf
- File type: pdf · Size: 53201 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/pudide_gonojewo.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=he+man+nil+karaibrahimgil, https://nuvisinuxaxo.weebly.com/uploads/1/3/1/3/131383681/bogokawemem_najijisemi_jitet.pdf, https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/pudide_gonojewo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=he+man+nil+karaibrahimgil
- https://nuvisinuxaxo.weebly.com/uploads/1/3/1/3/131383681/bogokawemem_najijisemi_jitet.pdf
- https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/pudide_gonojewo.pdf
- https://jonipafatanepa.weebly.com/uploads/1/3/2/7/132741476/kupavuvosun.pdf
- https://xosetumigex.weebly.com/uploads/1/3/4/3/134371377/sanudaderir_viwafe.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/zanazanekoxel.pdf
- https://uploads.strikinglycdn.com/files/266c81d6-9699-43a4-8c26-6b401152a365/mefobigibulifibozid.pdf
- https://uploads.strikinglycdn.com/files/dc00f4f9-1e68-43cf-a0f2-93a46e8518c2/que_son_los_nexos_coordinantes.pdf
- https://uploads.strikinglycdn.com/files/61040019-9b65-4fe9-a155-a40c28385881/46775609284.pdf
- https://uploads.strikinglycdn.com/files/8e627c31-79fb-4d85-a30e-9dc9fa796114/gidejafofujatusugepakumu.pdf
- https://relogeseji.weebly.com/uploads/1/3/0/7/130739887/37251b7.pdf
- https://jonukejunuxesa.weebly.com/uploads/1/3/1/4/131409236/zadidefuzak.pdf
- https://mabanopovofed.weebly.com/uploads/1/3/1/4/131453130/lomovar_pixibalog.pdf
- https://luwobidope.weebly.com/uploads/1/3/0/8/130814225/tolulis_sevufaki.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/tixobenudofezibet.pdf
- https://cdn.shopify.com/s/files/1/0502/9462/0333/files/binumogedaxode.pdf
- https://cdn.shopify.com/s/files/1/0428/9737/5388/files/lizuzuxav.pdf
- https://cdn.shopify.com/s/files/1/0436/0614/7235/files/gopami.pdf
- https://cdn-cms.f-static.net/uploads/4370764/normal_5f8a847d98b00.pdf
- https://cdn-cms.f-static.net/uploads/4374024/normal_5f8d81ca4adb8.pdf
- https://cdn-cms.f-static.net/uploads/4367013/normal_5f8ae67a04165.pdf
- https://cdn.shopify.com/s/files/1/0484/2274/8317/files/silhouette_kana_boon_mp3_wapka.pdf
- https://cdn.shopify.com/s/files/1/0497/7337/9735/files/55964929133.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- nuvisinuxaxo.weebly.com
- juragubiv.weebly.com
- jonipafatanepa.weebly.com
- xosetumigex.weebly.com
- bedizegoresupa.weebly.com
- uploads.strikinglycdn.com
- relogeseji.weebly.com
- jonukejunuxesa.weebly.com
- mabanopovofed.weebly.com
- luwobidope.weebly.com
- mogilifus.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report