MALICIOUS — 112cf8ce.pdf
MALICIOUS — 112cf8ce.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1cf0c2632e826b123f018d542fa884112b2ff1cf26167dff4bcf65674965d9a9 - SHA-1:
1b1994b7a9ea1b2ec44826e103d33746d398e86a - MD5:
83cb4dff8a6fd4c7bc8132a7085fd0e9 - ssdeep:
768:NgGzpDVpgzdoBWAp3CzFLmY0ioBwW1cYmmk7QjV/UPd8o4/za247hz:uGFBpNpyz4YMC+bm50BUPd/Ma247hz - TLSH:
T105328DF350ABED4C3AC79793ACAB1559704AC38872369750448CBB6CC1BC7ADAF10960 - Submitted as: 112cf8ce.pdf
- File type: pdf · Size: 45716 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/ramugimexixepaba.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=longman%20academic%20writing%20series%20down, https://cdn-cms.f-static.net/uploads/4367279/normal_5f874ebc3e357.pdf, https://cdn-cms.f-static.net/uploads/4366048/normal_5f86fb38596e7.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=longman%20academic%20writing%20series%20down
- https://cdn-cms.f-static.net/uploads/4367279/normal_5f874ebc3e357.pdf
- https://cdn-cms.f-static.net/uploads/4366048/normal_5f86fb38596e7.pdf
- https://cdn-cms.f-static.net/uploads/4365580/normal_5f889a5a18320.pdf
- https://uploads.strikinglycdn.com/files/7157f3f4-f826-4acf-970c-891e36fbec29/53767409334.pdf
- https://uploads.strikinglycdn.com/files/ae7aacb7-e43a-4635-9f39-ca05403af48b/topozidunekuru.pdf
- https://uploads.strikinglycdn.com/files/0cb6752c-23e9-4397-af67-8ef7fa161e3b/68324475022.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/ramugimexixepaba.pdf
- https://nikokabiliru.weebly.com/uploads/1/3/1/4/131409463/jalusupelesetuvo.pdf
- https://xumogimunosu.weebly.com/uploads/1/3/1/6/131607683/5213414.pdf
- https://dojulukasinu.weebly.com/uploads/1/3/0/7/130776790/jeburagu_xuzupu_bosurub_radomizen.pdf
- https://gikoberi.weebly.com/uploads/1/3/0/9/130969260/f035a.pdf
- https://site-1040096.mozfiles.com/files/1040096/62528027508.pdf
- https://site-1037073.mozfiles.com/files/1037073/gotolewapupesudevajufej.pdf
- https://besavikeneg.weebly.com/uploads/1/3/2/8/132815808/vipunaxokoni_guxojudixewa_gazaxovolegeb_jumemex.pdf
- https://fewevivib.weebly.com/uploads/1/3/0/8/130813821/bepabexobu_xodoxavu_lenusigobu_xadutedid.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/ratefunerod.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/475594.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/8767144.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/xopevu_vilugarokobijos_fimorekon.pdf
- https://nukevokisoget.weebly.com/uploads/1/3/2/7/132711970/c6878df49713.pdf
- https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/a7b88.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/batagebexi.pdf
- https://lodirunesu.weebly.com/uploads/1/3/0/8/130874391/8192911.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- guwomenod.weebly.com
- nikokabiliru.weebly.com
- xumogimunosu.weebly.com
- dojulukasinu.weebly.com
- gikoberi.weebly.com
- site-1040096.mozfiles.com
- site-1037073.mozfiles.com
- besavikeneg.weebly.com
- fewevivib.weebly.com
- dutitujazekap.weebly.com
- wepugimi.weebly.com
- dimaxafazeza.weebly.com
- jawasolasazilem.weebly.com
- nukevokisoget.weebly.com
- gevafitasib.weebly.com
- mojivimimujovo.weebly.com
- lodirunesu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report