MALICIOUS — pemup.pdf
MALICIOUS — pemup.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
60e9d6284b84a9316546cc35a2451cba8b11fe65fa1bc47793035fba0e55d3c8 - SHA-1:
cd8930202efbfc48854bf54d83991cf36996fa17 - MD5:
b45f6c1c365f9dbea87682226fffcfa5 - ssdeep:
1536:nGF/pkE/j8k4V0otVoEWVOon7lFJpRlAZ4i93SDVWXoytv1P:GF/p54V0ooEM7ltRlA4Dooyt1 - TLSH:
T13036AFF340A7DE8C7AC79B47A9B6156A614BC38D702657E044987B6CC87CAFC6F00650 - Submitted as: pemup.pdf
- File type: pdf · Size: 65542 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/b4b3eb38b.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=ejercicios%20de%20proporcionalidad%202%20eso, https://site-1037276.mozfiles.com/files/1037276/wovilojunogemegemez.pdf, https://site-1048220.mozfiles.com/files/1048220/6166935541.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=ejercicios%20de%20proporcionalidad%202%20eso
- https://site-1037276.mozfiles.com/files/1037276/wovilojunogemegemez.pdf
- https://site-1048220.mozfiles.com/files/1048220/6166935541.pdf
- https://site-1044185.mozfiles.com/files/1044185/71205229432.pdf
- https://uploads.strikinglycdn.com/files/910a969a-3fa9-458e-a117-49ebeafdfca7/lakovezet.pdf
- https://uploads.strikinglycdn.com/files/53a20cd7-9620-486f-bbd0-9f6579daa558/pigilinabiguz.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/b4b3eb38b.pdf
- https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/1429013.pdf
- https://povutepumik.weebly.com/uploads/1/3/2/7/132741486/4952957.pdf
- https://loguxofe.weebly.com/uploads/1/3/0/7/130775118/bc44ba.pdf
- https://uploads.strikinglycdn.com/files/7562a032-a006-4eea-a575-2fbeb199c4a6/zeduriwokanepedo.pdf
- https://uploads.strikinglycdn.com/files/e7e56ce6-f556-4489-ac47-e52b7fc95896/punefev.pdf
- https://uploads.strikinglycdn.com/files/3064c44e-7d4d-45ca-b6f5-320532fc570c/kuberidolimek.pdf
- https://uploads.strikinglycdn.com/files/8bdab8bd-d2c9-4b4a-8720-adf5af58b915/72057183452.pdf
- https://uploads.strikinglycdn.com/files/1002027b-663f-442b-9d1e-9a85a30e1dbe/kefodujo.pdf
- https://uploads.strikinglycdn.com/files/93dea412-5e52-4644-a9a0-306a30ac4bf0/26226684599.pdf
- https://uploads.strikinglycdn.com/files/727a8dfc-aac4-49f8-a294-18ca0b6daa3e/luxovalifafalejitifagara.pdf
- https://cdn-cms.f-static.net/uploads/4365541/normal_5f8715b8aa17d.pdf
- https://cdn-cms.f-static.net/uploads/4365607/normal_5f870ae861a0d.pdf
- https://cdn-cms.f-static.net/uploads/4366357/normal_5f8712f3df29b.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- site-1037276.mozfiles.com
- site-1048220.mozfiles.com
- site-1044185.mozfiles.com
- uploads.strikinglycdn.com
- gimejexoxixaza.weebly.com
- gevafitasib.weebly.com
- povutepumik.weebly.com
- loguxofe.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report