MALICIOUS — 6442289.pdf
MALICIOUS — 6442289.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2961b54a9010e662b07ee60dc21db2f0e39c18d35e4fb0a051c17d60e8131796 - SHA-1:
de5e14bb60e60ce2dc7f80b056beff225e317722 - MD5:
f47904830d51077010be040dedf8b781 - ssdeep:
1536:vGFdpWvsHpexrtrNkrX2f+99Hym8vX/rF2urBUdDXlXT7OS:eFdpWvK+7k19LiX/N9UdDX5r - TLSH:
T11938CFF35097ED8C7787275BADFA159A654AD78CB12693A104C8B73C94FC9AC2F00A01 - Submitted as: 6442289.pdf
- File type: pdf · Size: 81165 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/ef82e0d.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=l, https://xonuguzuv.weebly.com/uploads/1/3/1/3/131382030/povorom_vuwivoramivab.pdf, https://pejopazuzaguwoz.weebly.com/uploads/1/3/2/8/132815183/belunup.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=l
- https://xonuguzuv.weebly.com/uploads/1/3/1/3/131382030/povorom_vuwivoramivab.pdf
- https://pejopazuzaguwoz.weebly.com/uploads/1/3/2/8/132815183/belunup.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/ef82e0d.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/4d5351fbb209c0.pdf
- https://kelobutino.weebly.com/uploads/1/3/0/9/130969458/2189261.pdf
- https://rivisoni.weebly.com/uploads/1/3/0/7/130739016/bunup.pdf
- https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/moxokisarev.pdf
- https://vurofagulomefu.weebly.com/uploads/1/3/1/4/131452840/wefamamomeg_fapezerelog_rajokamoginena.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/3968285.pdf
- https://vewutaniwem.weebly.com/uploads/1/3/0/8/130873717/6eeed2758a.pdf
- https://pejopazuzaguwoz.weebly.com/uploads/1/3/2/8/132815183/naforinijuz-bujidogufolumig-xideleluveruda.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/zutilipevozafeguwu.pdf
- https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/6de4423.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/7304884.pdf
- https://site-1040990.mozfiles.com/files/1040990/72109433075.pdf
- https://site-1040798.mozfiles.com/files/1040798/95531700187.pdf
- https://site-1039437.mozfiles.com/files/1039437/17575526164.pdf
- https://cdn-cms.f-static.net/uploads/4366374/normal_5f875665b495b.pdf
- https://cdn-cms.f-static.net/uploads/4366045/normal_5f873c866cbcf.pdf
- https://cdn-cms.f-static.net/uploads/4366408/normal_5f8788c8d6913.pdf
- https://cdn-cms.f-static.net/uploads/4366000/normal_5f87045cc7312.pdf
- https://cdn-cms.f-static.net/uploads/4366305/normal_5f876e8840369.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- xonuguzuv.weebly.com
- pejopazuzaguwoz.weebly.com
- dutitujazekap.weebly.com
- zoxuzuxebexot.weebly.com
- kelobutino.weebly.com
- rivisoni.weebly.com
- babikovinemixe.weebly.com
- vurofagulomefu.weebly.com
- wepugimi.weebly.com
- vewutaniwem.weebly.com
- guwomenod.weebly.com
- jaserasozupog.weebly.com
- genigudepa.weebly.com
- site-1040990.mozfiles.com
- site-1040798.mozfiles.com
- site-1039437.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report