MALICIOUS — famedixotemapom.pdf
MALICIOUS — famedixotemapom.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5d2d1fab260cf9cb18de999ed8cbd72478ec4f0949903c5631ad480d1a961e0d - SHA-1:
1083754f9f3862494f2ab776a201dd99fedbd937 - MD5:
7da87d335023d4bb92b77a7d6212ac38 - ssdeep:
768:tgGzpDGctYyf5IEe6zZX0tyu+ed+JtE7i7qbjmTBrgS4sprXHK:OGFCQFjeNfAuiOGdrjrXHK - TLSH:
T116328DF351ABDD4C6A8AEF077EB71598508A87886032DB5044CC7B2DD4BC6BD2E10D51 - Submitted as: famedixotemapom.pdf
- File type: pdf · Size: 43874 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/6497588.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=car%20suspension%20types%20pdf, https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/6497588.pdf, https://cdn-cms.f-static.net/uploads/4415544/normal_5f97844ed1b4d.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=car%20suspension%20types%20pdf
- https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/6497588.pdf
- https://s3.amazonaws.com/rekibedafowow/77482460582.pdf
- https://s3.amazonaws.com/jebokizez/sukaw.pdf
- https://s3.amazonaws.com/henghuili-files/pevabujadiburakubug.pdf
- https://s3.amazonaws.com/busutafitufe/panthertown_valley_trail_map.pdf
- https://cdn-cms.f-static.net/uploads/4415544/normal_5f97844ed1b4d.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/8980310.pdf
- https://s3.amazonaws.com/sevoga/30347203.pdf
- https://uploads.strikinglycdn.com/files/75f51389-05b0-4327-accc-1099ce51826b/32940659103.pdf
- https://cdn-cms.f-static.net/uploads/4374366/normal_5f92aed47bc23.pdf
- https://uploads.strikinglycdn.com/files/75c9c5e7-3ace-445f-9dda-83a238b1fea1/53791224878.pdf
- https://s3.amazonaws.com/dinisemowoge/protein_synthesis_in_eukaryotic_cells.pdf
- https://uploads.strikinglycdn.com/files/adcc650f-cf9c-4134-9b83-bbe07861977e/como_obtener_el_peso_constante_de_un_crisol.pdf
- https://s3.amazonaws.com/fosawef/80405936695.pdf
- https://uploads.strikinglycdn.com/files/1544b5a3-2a0c-4bba-99f5-e0bd6815224c/4151770316.pdf
- https://seforurusux.weebly.com/uploads/1/3/4/1/134131879/nijavugid-vikotutasu.pdf
- https://uploads.strikinglycdn.com/files/ac0f21f1-a67d-4720-af1d-1cb4d2b4d19a/dapewulawubaz.pdf
- https://s3.amazonaws.com/kavitokolezub/apocrifos_del_antiguo_testamento_tomo_vi.pdf
- https://cdn-cms.f-static.net/uploads/4367640/normal_5f8b9bfc84498.pdf
- https://uploads.strikinglycdn.com/files/59fd1cca-60f9-473d-a445-5559b580dc83/94032147682.pdf
- https://uploads.strikinglycdn.com/files/a5c49454-d603-4e78-9e94-5ed6491ceb66/how_high_are_high_school_hurdles.pdf
- https://s3.amazonaws.com/susopuzupure/43612709105.pdf
- https://uploads.strikinglycdn.com/files/060befa1-b451-432f-ba6a-e02f56c39d58/95497844454.pdf
- https://xubikorapaja.weebly.com/uploads/1/3/4/3/134335605/tosojajovenidiz.pdf
Embedded domains
- cctraff.ru
- fodezamu.weebly.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- vuxozajuje.weebly.com
- uploads.strikinglycdn.com
- seforurusux.weebly.com
- xubikorapaja.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report