MALICIOUS — emerson_ewr20v4_dvd_recorder_vcr_combo_user_manual.pdf
MALICIOUS — emerson_ewr20v4_dvd_recorder_vcr_combo_user_manual.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
319c8f59ce877c3867b8401664544e6586c60a9a5ed2b8a0417c910c42c830bb - SHA-1:
99086e17bcc29d1fc1ffdba03d50cf2debc77127 - MD5:
348c11721f12191207ae48f53c0978e3 - ssdeep:
768:BgGzpDFQ/myfb0LMOJ9AFEyKYi9y7gDAymly+R01e06RcS/:yGFRbMOBpYlkEyiFKx6RcS/ - TLSH:
T1FC307AF3149FED8C7E879753EDA706966186C38872379B6010D8A32C84BC5BDAF11861 - Submitted as: emerson_ewr20v4_dvd_recorder_vcr_combo_user_manual.pdf
- File type: pdf · Size: 37889 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://sibakixode.weebly.com/uploads/1/3/2/8/132814768/8948163.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=emerson+ewr20v4+dvd+recorder+vcr+combo+user+manual, https://cdn.shopify.com/s/files/1/0266/9300/9604/files/blackstone_tailgater_combo_cover.pdf, https://cdn-cms.f-static.net/uploads/4368223/normal_5f8c212ed67d1.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=emerson+ewr20v4+dvd+recorder+vcr+combo+user+manual
- https://s3.amazonaws.com/leguvefu/76793399212.pdf
- https://s3.amazonaws.com/dumupa/zemakut.pdf
- https://s3.amazonaws.com/rerinago/53747880795.pdf
- https://s3.amazonaws.com/zesotat/mikuvepopivawazolitule.pdf
- https://s3.amazonaws.com/vonuxagupeduze/48341001668.pdf
- https://cdn.shopify.com/s/files/1/0266/9300/9604/files/blackstone_tailgater_combo_cover.pdf
- https://s3.amazonaws.com/sukedil/college_football_bowl_game_schedule.pdf
- https://s3.amazonaws.com/jozetej/55128823080.pdf
- https://s3.amazonaws.com/sugowubuf/neet_biology_sample_questions.pdf
- https://cdn-cms.f-static.net/uploads/4368223/normal_5f8c212ed67d1.pdf
- https://cdn-cms.f-static.net/uploads/4384461/normal_5f90bfa86c5c4.pdf
- https://cdn-cms.f-static.net/uploads/4374364/normal_5f8a055899fec.pdf
- https://cdn-cms.f-static.net/uploads/4376611/normal_5f8bddf754af6.pdf
- https://sibakixode.weebly.com/uploads/1/3/2/8/132814768/8948163.pdf
- https://sipasegeremiraf.weebly.com/uploads/1/3/4/4/134404187/zepajaresom.pdf
- https://bewupoterefi.weebly.com/uploads/1/3/1/3/131380107/6867849.pdf
- https://pidofuvu.weebly.com/uploads/1/3/0/7/130739764/9913158.pdf
- https://vewutaniwem.weebly.com/uploads/1/3/0/8/130873717/9243879.pdf
- https://zimiduninu.weebly.com/uploads/1/3/1/6/131637103/8774348.pdf
- https://pavowojavujide.weebly.com/uploads/1/3/1/3/131398322/jegufevomur-lewog-sibanogas.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/3731638.pdf
- https://tedovuja.weebly.com/uploads/1/3/4/4/134465286/mesalanopetik.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- s3.amazonaws.com
- cdn.shopify.com
- cdn-cms.f-static.net
- sibakixode.weebly.com
- sipasegeremiraf.weebly.com
- bewupoterefi.weebly.com
- pidofuvu.weebly.com
- vewutaniwem.weebly.com
- zimiduninu.weebly.com
- pavowojavujide.weebly.com
- gimejexoxixaza.weebly.com
- tedovuja.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report