MALICIOUS — b4e6966cf639ec.pdf
MALICIOUS — b4e6966cf639ec.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
36c9955f1a3ae3353994f0b6d6ac4f0cc478e8af8deaca85284358d8439b8129 - SHA-1:
61d50fb7b0a4e1d3752406a31718c1a1948e5933 - MD5:
746488ea6c597f9ae557fbc6ad744346 - ssdeep:
768:SgGzpDypXKTXSh0+x3eF+vDFOLdfa3JnLaoW8HppDxFSXJzmMF0t0wh:PGFOpXCyueMBfa5nKWpdFSXJzmyu0wh - TLSH:
T1A931AEF754A7EC4CBE862B07BDEA1091514DC388A277D7A01888B73DC4BC2BD6E10961 - Submitted as: b4e6966cf639ec.pdf
- File type: pdf · Size: 42643 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://mupibidegupek.weebly.com/uploads/1/3/0/8/130874042/pejixijesoba.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=mind%20power%20in%20the%2021st%20century, https://uploads.strikinglycdn.com/files/01aa82e1-5822-42ce-9176-d5e19fe2ec88/fufiverirazoposizapi.pdf, https://uploads.strikinglycdn.com/files/efd9ef80-e9d7-45a6-9ef0-01564d4ae831/97635935924.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=mind%20power%20in%20the%2021st%20century
- https://uploads.strikinglycdn.com/files/01aa82e1-5822-42ce-9176-d5e19fe2ec88/fufiverirazoposizapi.pdf
- https://uploads.strikinglycdn.com/files/efd9ef80-e9d7-45a6-9ef0-01564d4ae831/97635935924.pdf
- https://uploads.strikinglycdn.com/files/f2a12e5f-d8d4-4e9c-8bcf-aa159c639b10/witoraw.pdf
- https://mupibidegupek.weebly.com/uploads/1/3/0/8/130874042/pejixijesoba.pdf
- https://uploads.strikinglycdn.com/files/cc358b29-dd29-4455-ba7b-4100b248e202/65835949649.pdf
- https://uploads.strikinglycdn.com/files/1aeca644-80f8-438a-b245-ea4964644cc4/bumewapokegijoxovamej.pdf
- https://uploads.strikinglycdn.com/files/aaa923aa-7a9d-4af9-b9a4-2c76002e536e/zimalo.pdf
- https://uploads.strikinglycdn.com/files/9c3182f0-fd57-422c-8e3c-ed8a0738ddd7/57899037892.pdf
- https://uploads.strikinglycdn.com/files/1f427387-b581-464e-875f-6d00ae7c1777/44106671499.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/vepulakanug.pdf
- https://tejigenunonim.weebly.com/uploads/1/3/0/8/130813632/musub_noxevatug.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/jinitorip-bolag.pdf
- https://povutepumik.weebly.com/uploads/1/3/2/7/132741486/lejegumonivixaro.pdf
- https://site-1036932.mozfiles.com/files/1036932/96529581303.pdf
- https://site-1040036.mozfiles.com/files/1040036/78313931141.pdf
- https://site-1040238.mozfiles.com/files/1040238/zaveruda.pdf
- https://site-1036997.mozfiles.com/files/1036997/42400178663.pdf
- https://site-1036839.mozfiles.com/files/1036839/zilulekoxajopovi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- mupibidegupek.weebly.com
- mojivimimujovo.weebly.com
- tejigenunonim.weebly.com
- gimejexoxixaza.weebly.com
- povutepumik.weebly.com
- site-1036932.mozfiles.com
- site-1040036.mozfiles.com
- site-1040238.mozfiles.com
- site-1036997.mozfiles.com
- site-1036839.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report