MALICIOUS — 292e4.pdf
MALICIOUS — 292e4.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
593901f2112a7846a72577bd8407feb081d692af42fe3e06081d4fafcad24554 - SHA-1:
3873027c6e21560a8e95d3b8a2613cdc22861df1 - MD5:
94988f0ab48c2832e11166966d52cf49 - ssdeep:
768:OgGzpDHpSyYQ1ZmdDOooFh1R4jUKVUpXPMLg1plfjAzT7jQNLQ7O3l01uupw:rGFzpFFh1NQgRfjAH7sNV3l01uupw - TLSH:
T107329EF34597DC4C7A83ABC3ADA71998618AC28D7022EB50858C766CC97C2FD7F10961 - Submitted as: 292e4.pdf
- File type: pdf · Size: 46744 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://mupibidegupek.weebly.com/uploads/1/3/0/8/130874042/6752891a.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=minecraft%20asans%C3%B6r%20modu%201.7.10, https://uploads.strikinglycdn.com/files/f643c4ce-6435-42fa-a0df-2ffbb917dff0/lotowugubopejiludabaroral.pdf, https://uploads.strikinglycdn.com/files/b258fb82-6145-4ac2-865d-27c12f52726c/74374456099.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=minecraft%20asans%C3%B6r%20modu%201.7.10
- https://uploads.strikinglycdn.com/files/f643c4ce-6435-42fa-a0df-2ffbb917dff0/lotowugubopejiludabaroral.pdf
- https://uploads.strikinglycdn.com/files/b258fb82-6145-4ac2-865d-27c12f52726c/74374456099.pdf
- https://uploads.strikinglycdn.com/files/dbb22f4e-3195-4aa3-9023-1fa21dcae990/rubesijuwukop.pdf
- https://uploads.strikinglycdn.com/files/e921cd0f-b312-4a64-b131-247020b0beec/selajataxafibanukevidoses.pdf
- https://uploads.strikinglycdn.com/files/a944bed8-4e0e-4881-9864-12a745ff09d2/78488532606.pdf
- https://mupibidegupek.weebly.com/uploads/1/3/0/8/130874042/6752891a.pdf
- https://narogigadi.weebly.com/uploads/1/3/0/8/130874066/c2099e721b.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/36ce75ac.pdf
- https://site-1043934.mozfiles.com/files/1043934/fuwedizikumesagelujazoj.pdf
- https://site-1039897.mozfiles.com/files/1039897/51425631453.pdf
- https://site-1042821.mozfiles.com/files/1042821/71949022760.pdf
- https://uploads.strikinglycdn.com/files/c857e62f-32cc-48dd-b555-0f30a1843890/42290136859.pdf
- https://uploads.strikinglycdn.com/files/e9730293-2682-4157-a519-06d20b556680/tuvitebojigedinabup.pdf
- https://uploads.strikinglycdn.com/files/664e4688-0865-4265-b4ee-f47fce408353/jijoruxibaxojexagifubi.pdf
- https://uploads.strikinglycdn.com/files/c534be69-2d6c-40bf-a1d7-aebcbf395b1a/zudixugafifufaroparaxo.pdf
- https://cdn.shopify.com/s/files/1/0493/7098/8710/files/51881729407.pdf
- https://cdn.shopify.com/s/files/1/0432/7568/1947/files/c_cstring_length.pdf
- https://cdn.shopify.com/s/files/1/0433/6422/1077/files/riccar_central_vacuum_reviews.pdf
- https://cdn.shopify.com/s/files/1/0431/1757/6354/files/zifaru.pdf
- https://cdn.shopify.com/s/files/1/0438/4122/4869/files/switch_iphone_to_android_imessage.pdf
- https://cdn.shopify.com/s/files/1/0431/6453/2900/files/guardians_of_the_galaxy_google_drive_reddit.pdf
- https://cdn.shopify.com/s/files/1/0438/2644/6498/files/margarita_gift_basket_australia.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- mupibidegupek.weebly.com
- narogigadi.weebly.com
- dutitujazekap.weebly.com
- site-1043934.mozfiles.com
- site-1039897.mozfiles.com
- site-1042821.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report