MALICIOUS — mobir.pdf
MALICIOUS — mobir.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3e2b1f4a0f57839ccc32ef4ee0cbd9484bae431b32c9872fd82320a7a0001de3 - SHA-1:
59cf1ef3b2f23f391f299b8811d4df04bf20d3ec - MD5:
9431ff547e04718384f148351b6edc7e - ssdeep:
768:jugGzpDWpx+Kkx/OIltnvqLA1GDICW/6JKfozP2HmVOLoUtTx1fb7aNg9:vGFipx+KmKmGDZYozP2HmVrUpDaNg9 - TLSH:
T111328DF310A7EE4CBA86EB476EAE3459504AE74C603297A049DC776CC4BC7BD6E00911 - Submitted as: mobir.pdf
- File type: pdf · Size: 47072 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://tevirilozarenov.weebly.com/uploads/1/3/2/6/132695732/5189618.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=air%20conditioning%20operation%20pdf, https://genifefesabido.weebly.com/uploads/1/3/3/9/133999330/d4121931.pdf, https://tevirilozarenov.weebly.com/uploads/1/3/2/6/132695732/5189618.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=air%20conditioning%20operation%20pdf
- https://genifefesabido.weebly.com/uploads/1/3/3/9/133999330/d4121931.pdf
- https://tevirilozarenov.weebly.com/uploads/1/3/2/6/132695732/5189618.pdf
- https://kikuriniwabutip.weebly.com/uploads/1/3/4/4/134440093/vubosunudotin.pdf
- https://xebikazogede.weebly.com/uploads/1/3/2/7/132740990/6d371b4a243e2c5.pdf
- https://s3.amazonaws.com/wilugugo/rudufowo.pdf
- https://s3.amazonaws.com/vuraradaso/kiran_bank_math_book.pdf
- https://s3.amazonaws.com/henghuili-files2/22_cal_gatling_gun_plans.pdf
- https://s3.amazonaws.com/zirojopemup/78388755739.pdf
- https://s3.amazonaws.com/subud/41072957772.pdf
- https://uploads.strikinglycdn.com/files/c92485c9-7d33-4816-9ac3-5b5c1e8c2f6f/97417727851.pdf
- https://uploads.strikinglycdn.com/files/658502ff-11df-48fd-9da4-0a1f0cf1257f/vefubojasewez.pdf
- https://uploads.strikinglycdn.com/files/d19e6668-9e6e-411b-9c31-9bca30449710/68701336704.pdf
- https://uploads.strikinglycdn.com/files/53cc9016-215e-4e3d-accc-052697eef4bf/barat.pdf
- https://uploads.strikinglycdn.com/files/28f91151-43a8-4fa0-9fde-a99456a118af/wibaraluna.pdf
- https://uploads.strikinglycdn.com/files/d80a7ed5-cb37-4776-8096-62db41c365fa/judepuduvanex.pdf
- https://uploads.strikinglycdn.com/files/47a39ce7-42c3-407f-be55-8f2a856b8b7c/58386755003.pdf
- https://uploads.strikinglycdn.com/files/8bf02e88-71d9-43d1-8058-3c9b10bf3c1c/49163883514.pdf
- https://uploads.strikinglycdn.com/files/458fa5a6-8682-4024-8844-931c65082ddf/zufezirepegawegi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- genifefesabido.weebly.com
- tevirilozarenov.weebly.com
- kikuriniwabutip.weebly.com
- xebikazogede.weebly.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report