MALICIOUS — liner_bepekefovuzow_mipudu_bajit.pdf
MALICIOUS — liner_bepekefovuzow_mipudu_bajit.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 1 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1db873835673ec6772c90afa9bcb5c80dbe7182e5306045db7cd4cf37bf53dcf - SHA-1:
983b4ea1a41c41c97e16086ce1daee7a4b727808 - MD5:
0e79dbc4d161706765c0ecf1a7ee8e38 - ssdeep:
768:zgGzpDppylWfHauETI9+mQmLAcOKKR9hINTAkSCIbgQY:MGFNpygfbnLLOKKfiNTAkSCIbRY - TLSH:
T13F305CF350A7DD8C7B8B6B03AEBB155D544AD7896036D7904488262C947CAFE3F00A61 - Submitted as: liner_bepekefovuzow_mipudu_bajit.pdf
- File type: pdf · Size: 39054 bytes
- Verdict: malicious (71/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://cdn-cms.f-static.net/uploads/4366625/normal_5f8776874d873.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=bridge%20engineering%20book%20pdf, https://cdn-cms.f-static.net/uploads/4367308/normal_5f875b9554077.pdf, https://cdn-cms.f-static.net/uploads/4368229/normal_5f87672d42ebe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=bridge%20engineering%20book%20pdf
- https://cdn-cms.f-static.net/uploads/4367308/normal_5f875b9554077.pdf
- https://cdn-cms.f-static.net/uploads/4368229/normal_5f87672d42ebe.pdf
- https://cdn-cms.f-static.net/uploads/4368989/normal_5f87daf5b0038.pdf
- https://cdn-cms.f-static.net/uploads/4366625/normal_5f8776874d873.pdf
- https://cdn-cms.f-static.net/uploads/4366947/normal_5f87a113dade9.pdf
- https://site-1040795.mozfiles.com/files/1040795/nebatur.pdf
- https://site-1037275.mozfiles.com/files/1037275/numivosikekenufovubum.pdf
- https://site-1039633.mozfiles.com/files/1039633/72228431171.pdf
- https://site-1038674.mozfiles.com/files/1038674/72703887541.pdf
- https://site-1044015.mozfiles.com/files/1044015/xasubaxidapoboge.pdf
- https://jiwepurojal.weebly.com/uploads/1/3/0/7/130775762/pigix.pdf
- https://fidegobopoj.weebly.com/uploads/1/3/2/8/132815019/9028306.pdf
- https://kelobutino.weebly.com/uploads/1/3/0/9/130969458/6977354.pdf
- https://rajomiluti.weebly.com/uploads/1/3/2/6/132682989/legifezufusijelusexa.pdf
- https://lodirunesu.weebly.com/uploads/1/3/0/8/130874391/7774024.pdf
- https://uploads.strikinglycdn.com/files/757f998b-35aa-4757-ac3a-63f64e553dfc/dokujike.pdf
- https://uploads.strikinglycdn.com/files/e073f63d-f258-491e-834d-cb3195add1d8/pugojabezizolufojatavak.pdf
- https://uploads.strikinglycdn.com/files/738ce4e8-001e-4ea4-80fd-017da8fcc94b/noxonur.pdf
- https://uploads.strikinglycdn.com/files/0a706d44-37f2-49db-9494-7678b5d0d286/32090953331.pdf
- https://uploads.strikinglycdn.com/files/029a2271-e3ee-4ace-bec3-881c57e2c2ec/kuputofu.pdf
- https://site-1041483.mozfiles.com/files/1041483/54065116055.pdf
- https://site-1037026.mozfiles.com/files/1037026/4789707624.pdf
- https://site-1039888.mozfiles.com/files/1039888/mibamud.pdf
- https://site-1041082.mozfiles.com/files/1041082/dabazororep.pdf
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- site-1040795.mozfiles.com
- site-1037275.mozfiles.com
- site-1039633.mozfiles.com
- site-1038674.mozfiles.com
- site-1044015.mozfiles.com
- jiwepurojal.weebly.com
- fidegobopoj.weebly.com
- kelobutino.weebly.com
- rajomiluti.weebly.com
- lodirunesu.weebly.com
- uploads.strikinglycdn.com
- site-1041483.mozfiles.com
- site-1037026.mozfiles.com
- site-1039888.mozfiles.com
- site-1041082.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report