MALICIOUS — 8522249.pdf
MALICIOUS — 8522249.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 1 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4b4bb659de04c167358fb1a8a75052aa6ae8051ab55b826d157fc358db224afe - SHA-1:
9e1d14e5328751a04e2fe00b944d3e0a19794a0e - MD5:
b74df971b632d19d7d5c145b41018bdb - ssdeep:
768:qgGzpDYIZnPU5xNCLyUt6Lp5iufAT/wlf2LYzKR9A0gZnT/jznZ:3GFMbLs4lf2LSKRqZDHnZ - TLSH:
T1C3316CF314ABED8C7B8BAB03ADA7115A648AD74C6237DB50448C676CD5BC5BD7E00820 - Submitted as: 8522249.pdf
- File type: pdf · Size: 40815 bytes
- Verdict: malicious (71/100)
Detections (1 of 53 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/rimotipa.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=theorizing%20surveillance%20the%20panopticon%20and%20beyond%20pdf, https://lilawowawumoxo.weebly.com/uploads/1/3/1/4/131453384/keruwab-jowovalab.pdf, https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/dekegu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=theorizing%20surveillance%20the%20panopticon%20and%20beyond%20pdf
- https://lilawowawumoxo.weebly.com/uploads/1/3/1/4/131453384/keruwab-jowovalab.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/dekegu.pdf
- https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/rimotipa.pdf
- https://cdn.shopify.com/s/files/1/0439/4732/7646/files/jogexiwim.pdf
- https://cdn.shopify.com/s/files/1/0496/2746/3833/files/summoners_war_labyrinth_guide_reddit.pdf
- https://cdn.shopify.com/s/files/1/0481/3960/0021/files/60698909315.pdf
- https://cdn.shopify.com/s/files/1/0430/9372/1255/files/zovovajaludatadebebutadi.pdf
- https://cdn.shopify.com/s/files/1/0435/0600/8216/files/hd_camera_apps_for_android.pdf
- https://uploads.strikinglycdn.com/files/61fe6894-47fa-410b-b373-e373fe11dac7/sekekaraxatafedagej.pdf
- https://uploads.strikinglycdn.com/files/1b119daf-9bd5-46d0-a19f-dd2c3994ce86/67046495161.pdf
- https://s3.amazonaws.com/subud/56894979566.pdf
- https://s3.amazonaws.com/henghuili-files2/ancient_history_short_notes_in_hindi.pdf
- https://s3.amazonaws.com/xanebavifamopez/seoul_metro_map_2018.pdf
- https://s3.amazonaws.com/wilugugo/hotel_california_guitar_chords.pdf
- https://s3.amazonaws.com/henghuili-files/bullying_el_acoso_escolar_libro.pdf
- https://cdn.shopify.com/s/files/1/0502/5421/7388/files/46125932544.pdf
- https://cdn.shopify.com/s/files/1/0495/4646/1336/files/minecraft_blacksmith_house_design.pdf
- https://cdn.shopify.com/s/files/1/0496/4243/8809/files/minecraft_titans_mod_witherzilla.pdf
- https://cdn.shopify.com/s/files/1/0484/7773/3019/files/sonya_guide_royal_crown.pdf
- https://cdn.shopify.com/s/files/1/0437/1048/0533/files/65730265137.pdf
- https://cdn-cms.f-static.net/uploads/4375518/normal_5f9128790c62e.pdf
- https://cdn-cms.f-static.net/uploads/4365547/normal_5f8954f596bc7.pdf
- https://cdn-cms.f-static.net/uploads/4365642/normal_5f885372f20bb.pdf
- https://cdn-cms.f-static.net/uploads/4372100/normal_5f90438dd7a42.pdf
Embedded domains
- cctraff.ru
- lilawowawumoxo.weebly.com
- bedizegoresupa.weebly.com
- juragubiv.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report