MALICIOUS — 10a549854.pdf
MALICIOUS — 10a549854.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1eb5347ac0c29f05d397f42b3bd47924bbb9984b846db343633eaa14092d4c3c - SHA-1:
cd6c1f394f6aa52c826a1567b8a7a0f277c2b6b1 - MD5:
4673083679407938ccf7c73e7b194045 - ssdeep:
768:6gGzpDmp5kVF/wbprIcVJ3KsGZfetYgfsoZIFHfwcVrebCmonuWvrmVpy:nGFSppmcV0sPnfKHffVrSSdvSVpy - TLSH:
T1BA339DF71067EC8C3A4ADB039DAB055D6186D78DA172E69048C8772CD4BC6FE6F00A51 - Submitted as: 10a549854.pdf
- File type: pdf · Size: 48566 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/18ad995.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=siberian%20husky%20training%20guide%20pdf, https://uploads.strikinglycdn.com/files/b8032020-0ce7-458e-9822-a4f8af08f20c/pimajawur.pdf, https://uploads.strikinglycdn.com/files/dcbd4dba-acb7-4145-9c2b-0d0396710e31/vuzopixasizatijeduz.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=siberian%20husky%20training%20guide%20pdf
- https://uploads.strikinglycdn.com/files/b8032020-0ce7-458e-9822-a4f8af08f20c/pimajawur.pdf
- https://uploads.strikinglycdn.com/files/dcbd4dba-acb7-4145-9c2b-0d0396710e31/vuzopixasizatijeduz.pdf
- https://uploads.strikinglycdn.com/files/6f4875ab-4997-46bf-a480-7d19109cf3fc/jazanubotivodugipupe.pdf
- https://uploads.strikinglycdn.com/files/d2afc707-ac59-400e-a923-28af44426a21/68623278230.pdf
- https://gazesomudari.weebly.com/uploads/1/3/1/0/131070071/wiwubop.pdf
- https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/532013.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/jolupafulikatasiz.pdf
- https://gurigibafex.weebly.com/uploads/1/3/0/7/130739571/dobogejawizil.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/18ad995.pdf
- https://cdn-cms.f-static.net/uploads/4366007/normal_5f8f4535d3f55.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f874a6a8d743.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/nipomomuka_gisotufeje.pdf
- https://putigazabikikim.weebly.com/uploads/1/3/2/6/132682718/dd82abe0.pdf
- https://tenikekiso.weebly.com/uploads/1/3/0/7/130775729/9ca55dd.pdf
- https://s3.amazonaws.com/subud/autonomous_emergency_braking_system.pdf
- https://s3.amazonaws.com/zirojopemup/96252875525.pdf
- https://s3.amazonaws.com/wonoti/forward_contract_act.pdf
- https://s3.amazonaws.com/fadedosi/the_weather_worksheets_for_kindergarten.pdf
- https://s3.amazonaws.com/fizup/brushless_dc_servo_motor.pdf
- https://cdn.shopify.com/s/files/1/0502/9661/9193/files/nitro_7_kuyhaa.pdf
- https://cdn.shopify.com/s/files/1/0488/0623/2229/files/organic_chemistry_quiz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- gazesomudari.weebly.com
- sesuwulot.weebly.com
- vozunutav.weebly.com
- gurigibafex.weebly.com
- dutitujazekap.weebly.com
- cdn-cms.f-static.net
- jakedekokobara.weebly.com
- putigazabikikim.weebly.com
- tenikekiso.weebly.com
- s3.amazonaws.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report