MALICIOUS — 6c2aa.pdf
MALICIOUS — 6c2aa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
16821d6661af0ef828db4a327c4b41606dc56205492d0ec3c8afe1cdc2118228 - SHA-1:
8d05a366c76b10572d70c8596ab0e62c75ee8b34 - MD5:
b6cd19b046eb1c254ad09dd965eab214 - ssdeep:
1536:nhGFqeSci5F7oMY8a8C7ylRv262gXi1x:EFqeFMzDGylRe61q - TLSH:
T132338EF31097ED8C7A879B03ADAF25956189C78C7237A7601488772CC47C2ADBF50860 - Submitted as: 6c2aa.pdf
- File type: pdf · Size: 50487 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/tifuxasorelav-sunagutigu-gikisifexixabot.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=water%20and%20power%20a%20california%20heist%20worksheet%20answers, https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/tifuxasorelav-sunagutigu-gikisifexixabot.pdf, https://tudupumodowi.weebly.com/uploads/1/3/1/4/131406798/guteporakew.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=water%20and%20power%20a%20california%20heist%20worksheet%20answers
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/tifuxasorelav-sunagutigu-gikisifexixabot.pdf
- https://tudupumodowi.weebly.com/uploads/1/3/1/4/131406798/guteporakew.pdf
- https://fuparududewon.weebly.com/uploads/1/3/1/8/131856041/terapil.pdf
- https://kokexofagisukop.weebly.com/uploads/1/3/2/7/132710589/bovajilamivakota.pdf
- https://besajiti.weebly.com/uploads/1/3/1/8/131856076/5665386.pdf
- https://s3.amazonaws.com/sabegokek/buvudusalosijinumof.pdf
- https://s3.amazonaws.com/regovadeje/rationale_zahlen_aufgaben_mit_lsungen.pdf
- https://s3.amazonaws.com/banula/mp_census_2011_in_hindi.pdf
- https://s3.amazonaws.com/zemigiduwagafu/propiedades_arandanos.pdf
- https://s3.amazonaws.com/kisimujuk/33399120615.pdf
- https://cdn-cms.f-static.net/uploads/4383577/normal_5f8bd6b9e054b.pdf
- https://cdn-cms.f-static.net/uploads/4371495/normal_5f8ff3bfc4bce.pdf
- https://cdn-cms.f-static.net/uploads/4378846/normal_5f8b4fdb03d86.pdf
- https://cdn-cms.f-static.net/uploads/4370740/normal_5f91005eba6d7.pdf
- https://cdn-cms.f-static.net/uploads/4366375/normal_5f95b56ad9b39.pdf
- https://cdn-cms.f-static.net/uploads/4374540/normal_5f8cafa446677.pdf
- https://cdn-cms.f-static.net/uploads/4371240/normal_5f8a9e59254d2.pdf
- https://uploads.strikinglycdn.com/files/38d8cf57-846e-4664-964e-d0f2aa80a0bd/botw_kara_kara_bazaar.pdf
- https://uploads.strikinglycdn.com/files/cdc0d84f-9f5f-4bbf-9159-4590fdea3205/33003763943.pdf
- https://uploads.strikinglycdn.com/files/88defb70-d537-4c36-9f14-081442b027dc/33023926092.pdf
- https://uploads.strikinglycdn.com/files/c63906f5-2b3e-49ee-94fb-8c27dfafd0d1/werovipuwuvodasod.pdf
- https://uploads.strikinglycdn.com/files/56d0032d-b29d-45a3-8671-bcb4de766eb8/ratubupolivogerurimule.pdf
- https://naxedomabaxa.weebly.com/uploads/1/3/1/6/131606472/debatepevuvo-zolomebisusuwug-lewanujozev-vikude.pdf
- https://korodaziso.weebly.com/uploads/1/3/0/7/130740443/3823229.pdf
Embedded domains
- cctraff.ru
- genigudepa.weebly.com
- tudupumodowi.weebly.com
- fuparududewon.weebly.com
- kokexofagisukop.weebly.com
- besajiti.weebly.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- naxedomabaxa.weebly.com
- korodaziso.weebly.com
- bovitala.weebly.com
- sanuvexugivi.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report