MALICIOUS — 611bef74.pdf
MALICIOUS — 611bef74.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
33bdf4d20336c05aa6d69a4144abb08843dd27a69f6e687f33c39883bd9ef48d - SHA-1:
d15e09e7db15ed526e7ebcc4b71c7bb1c0b31c12 - MD5:
ff18f076b07ababd749b6015d1a61439 - ssdeep:
768:LgGzpDKpOnukoZhYKgC2FJgAm74sEemUq4vsT80fbhWda+f:0GFupCyh+J6BEeNqPrbkda+f - TLSH:
T179318EF31097ED8C768E67039EAB109E6086C78EA133D65015C83B7DE0BC6BD6E10925 - Submitted as: 611bef74.pdf
- File type: pdf · Size: 40699 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://mupibidegupek.weebly.com/uploads/1/3/0/8/130874042/8130356.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=township%20abbreviation%20usps, https://site-1038714.mozfiles.com/files/1038714/dedepa.pdf, https://site-1043456.mozfiles.com/files/1043456/muvavimutop.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=township%20abbreviation%20usps
- https://site-1038714.mozfiles.com/files/1038714/dedepa.pdf
- https://site-1043456.mozfiles.com/files/1043456/muvavimutop.pdf
- https://site-1037884.mozfiles.com/files/1037884/bokiruvupowavasi.pdf
- https://site-1038927.mozfiles.com/files/1038927/94803043536.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/475594.pdf
- https://mupibidegupek.weebly.com/uploads/1/3/0/8/130874042/8130356.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/bawap.pdf
- https://vuxilimibipemop.weebly.com/uploads/1/3/1/4/131453056/0a3d7442fdd232e.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/xekena.pdf
- https://site-1039604.mozfiles.com/files/1039604/10569575271.pdf
- https://site-1040250.mozfiles.com/files/1040250/fokebi.pdf
- https://site-1037889.mozfiles.com/files/1037889/foruluvaxezakefafuli.pdf
- https://damijuvik.weebly.com/uploads/1/3/1/3/131381376/buwupi.pdf
- https://xonimitofowe.weebly.com/uploads/1/3/2/6/132682232/4235942.pdf
- https://cdn.shopify.com/s/files/1/0484/3012/1112/files/google_search_tricks_filetype.pdf
- https://cdn.shopify.com/s/files/1/0439/0957/8904/files/avgo_earnings_date_history.pdf
- https://cdn.shopify.com/s/files/1/0432/4936/9252/files/information_security_policy_2020.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1038714.mozfiles.com
- site-1043456.mozfiles.com
- site-1037884.mozfiles.com
- site-1038927.mozfiles.com
- wepugimi.weebly.com
- mupibidegupek.weebly.com
- jatorogerujew.weebly.com
- vuxilimibipemop.weebly.com
- xojerajap.weebly.com
- site-1039604.mozfiles.com
- site-1040250.mozfiles.com
- site-1037889.mozfiles.com
- damijuvik.weebly.com
- xonimitofowe.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report