MALICIOUS — 192083.pdf
MALICIOUS — 192083.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5371e3347524b74c66d3cb58cdaf2fa000cef034f5e7ff1a6dc19cb230d2cb1c - SHA-1:
a596ea23330948b96caf001675ab9956d5951867 - MD5:
11d7665ac4d9bdeb244d8b84eeeb1950 - ssdeep:
1536:JGFBRPF5/CKOMg0W2Izvhn5VUXXqbI3zOluD/OIV4VuwqgHEZtY5Lg1i461u+3NZ:cFBRvKKf79I+XqXs/rKpHEyuGv3NMq/ - TLSH:
T19B3DF1FB82C7CD0C6F8B67476ABA241A554E834D1136EA6046EC766DC8FC3BD6E81401 - Submitted as: 192083.pdf
- File type: pdf · Size: 130225 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/8925184.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=philip%20kotler%20marketing%20mix%20pdf, https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/8925184.pdf, https://fotejisatowonu.weebly.com/uploads/1/3/2/3/132302873/fe2254e67d65d.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=philip%20kotler%20marketing%20mix%20pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/8925184.pdf
- https://fotejisatowonu.weebly.com/uploads/1/3/2/3/132302873/fe2254e67d65d.pdf
- https://uploads.strikinglycdn.com/files/3ed9ad6b-337c-49be-a620-80720b0d119a/najovodulexizupubabi.pdf
- https://zukamukenipebo.weebly.com/uploads/1/3/1/3/131380388/2672089.pdf
- https://s3.amazonaws.com/naxizugenabi/cardinal_utility_analysis_of_demand.pdf
- https://gutugifowofe.weebly.com/uploads/1/3/1/6/131606479/7483228.pdf
- https://zavisedifigi.weebly.com/uploads/1/3/4/3/134316550/9509058.pdf
- https://uploads.strikinglycdn.com/files/9217f19e-a21f-49ae-af09-41a7e3259b39/turilli_lione_rhapsody_zero_gravity_download.pdf
- https://s3.amazonaws.com/falevi/calvinismo_ou_arminianismo.pdf
- https://cdn.shopify.com/s/files/1/0432/2679/2093/files/skip_trowel_texture_mix.pdf
- https://cdn.shopify.com/s/files/1/0484/7468/5594/files/superlative_adjective_worksheet_for_grade_3.pdf
- https://cdn.shopify.com/s/files/1/0434/1858/3192/files/90322653763.pdf
- https://cdn.shopify.com/s/files/1/0435/3540/1112/files/perimeter_of_a_half_circle_and_rectangle.pdf
- https://cdn.shopify.com/s/files/1/0477/1974/3644/files/connect_gamepad_to_android_tv_box.pdf
- https://uploads.strikinglycdn.com/files/b5309867-2c8b-4293-9a71-71d0c896d57d/63183086414.pdf
- https://cdn.shopify.com/s/files/1/0468/8432/3485/files/siratadawurumuz.pdf
- https://banafazag.weebly.com/uploads/1/3/4/3/134325205/6554990.pdf
- https://uploads.strikinglycdn.com/files/b3df661d-f26c-4eb6-b3cc-95ad4d7b02b9/34222389077.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- vuxozajuje.weebly.com
- fotejisatowonu.weebly.com
- uploads.strikinglycdn.com
- zukamukenipebo.weebly.com
- s3.amazonaws.com
- gutugifowofe.weebly.com
- zavisedifigi.weebly.com
- cdn.shopify.com
- banafazag.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report