MALICIOUS — sogup.pdf
MALICIOUS — sogup.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
28cd9f0aede85b17e61563b30c9fd033ecabd58703787fdb573c1112316d1bb7 - SHA-1:
63994b8be4b749cc4dd9ad4716cc38829438fa53 - MD5:
924a8607036c72fd922660c056ce02da - ssdeep:
768:DgGzpDkpWtoqVCwpWIcZakSYieqqQSDbnCEdAanLFoQGFaw1+YB:8GFwpW27ijCGEdA+xoQGku+YB - TLSH:
T1DE33AEF310A7ED4C7A87AB435DAB1129558AC3882237EB9094DC7A2ED1BC1BD7E00D51 - Submitted as: sogup.pdf
- File type: pdf · Size: 47820 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://povutepumik.weebly.com/uploads/1/3/2/7/132741486/dcfa4214ba8d2d9.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=pelicula%20vals%20conmigo, https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/8709547.pdf, https://jemiwuwavaza.weebly.com/uploads/1/3/0/8/130814288/bibesekukemugedovofa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=pelicula%20vals%20conmigo
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/8709547.pdf
- https://jemiwuwavaza.weebly.com/uploads/1/3/0/8/130814288/bibesekukemugedovofa.pdf
- https://povutepumik.weebly.com/uploads/1/3/2/7/132741486/dcfa4214ba8d2d9.pdf
- https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/japixij.pdf
- https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/fazijopaf.pdf
- https://uploads.strikinglycdn.com/files/4c2fed06-60d1-4187-91b5-e402cdc19e0f/29828972000.pdf
- https://uploads.strikinglycdn.com/files/bf5ff45f-6946-40c1-b057-a1bd1c0fb4dd/dinoregenitugimuroweru.pdf
- https://uploads.strikinglycdn.com/files/1f767b54-3425-4fec-9883-9cf2eb9b6547/14473339943.pdf
- https://uploads.strikinglycdn.com/files/8bf53174-9cb1-4c7c-9088-06a3b5aecd91/81664674757.pdf
- https://cdn-cms.f-static.net/uploads/4366341/normal_5f87253a6b850.pdf
- https://cdn-cms.f-static.net/uploads/4369313/normal_5f87af361d1b9.pdf
- https://uploads.strikinglycdn.com/files/512932c2-f495-416e-87e2-f8c6b51d30ec/dotikamujanawirofurilav.pdf
- https://uploads.strikinglycdn.com/files/552bc072-9a97-404b-b423-7ea2b176ab9b/vatelajokiditoruzudozonup.pdf
- https://uploads.strikinglycdn.com/files/1ea51aea-79b9-4421-bfd0-7233f7491b53/80837045194.pdf
- https://uploads.strikinglycdn.com/files/649e97f9-0488-4a92-836b-83e41942c88a/vilozadozurolifiwewituv.pdf
- https://uploads.strikinglycdn.com/files/05be6893-7ae8-43fa-a61e-13949ed40f52/kekakugewirefa.pdf
- https://uploads.strikinglycdn.com/files/f531d8fb-c5ef-42ee-834e-b173859e055f/lifujekipabiniwijojazava.pdf
- https://uploads.strikinglycdn.com/files/841641aa-fb82-45b3-959c-c3282f8a4456/posubanepum.pdf
- https://uploads.strikinglycdn.com/files/76efbbb4-28ba-4a26-9820-f3ea7832bb3e/91965211248.pdf
- https://uploads.strikinglycdn.com/files/2c690ba7-14da-4fc7-a597-c80d8fb75ce0/kenerobakizododefetoso.pdf
- https://cdn.shopify.com/s/files/1/0496/0544/3736/files/more_adventures_of_the_great_brain.pdf
- https://cdn.shopify.com/s/files/1/0482/2754/9338/files/16828163997.pdf
- https://cdn.shopify.com/s/files/1/0496/7258/5373/files/7252318777.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- bedizegoresupa.weebly.com
- jemiwuwavaza.weebly.com
- povutepumik.weebly.com
- babikovinemixe.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report