MALICIOUS — mudepuwizebaselibasu.pdf
MALICIOUS — mudepuwizebaselibasu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 1 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6362ff1050c9d4cfe9e2e7be2b177eb329b03826df79fc0a1910845221974284 - SHA-1:
1c9642240558cc27c8f7dc3f1c6ffdca33bffc40 - MD5:
a43998cdddaded6ff919cf1ac02d25c6 - ssdeep:
768:2gGzpDBe96bLLDOZzRoepOkxo1R/9qB4mBS5wyu25ARjO7qTZJ4sE3pdUw:jGFNekb7N15wyhARjI0w - TLSH:
T180325BF300A3ED8C7A87DB03ADAB256C5589DB496132A7644488A72DC8BC77E7F50910 - Submitted as: mudepuwizebaselibasu.pdf
- File type: pdf · Size: 44124 bytes
- Verdict: malicious (71/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://tenagudewujuga.weebly.com/uploads/1/3/1/1/131164273/rujetuze-pisixi.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=american%20heart%20association%20bls%20manual, https://cdn-cms.f-static.net/uploads/4365594/normal_5f87559db42dd.pdf, https://cdn-cms.f-static.net/uploads/4365600/normal_5f87659e23676.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=american%20heart%20association%20bls%20manual
- https://cdn-cms.f-static.net/uploads/4365594/normal_5f87559db42dd.pdf
- https://cdn-cms.f-static.net/uploads/4365600/normal_5f87659e23676.pdf
- https://cdn-cms.f-static.net/uploads/4366040/normal_5f87f1088d95d.pdf
- https://cdn-cms.f-static.net/uploads/4367635/normal_5f884786cee2f.pdf
- https://tenagudewujuga.weebly.com/uploads/1/3/1/1/131164273/rujetuze-pisixi.pdf
- https://vevejeda.weebly.com/uploads/1/3/0/7/130776099/gomesepopudikapesozi.pdf
- https://sepikupi.weebly.com/uploads/1/3/0/7/130738949/4399179.pdf
- https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/f895c9.pdf
- https://cdn.shopify.com/s/files/1/0432/7977/7952/files/las_venturas_lakewood_mall.pdf
- https://cdn.shopify.com/s/files/1/0482/8944/8091/files/statistical_inference_casella_berger.pdf
- https://site-1037082.mozfiles.com/files/1037082/vufokefosevusarevi.pdf
- https://site-1043608.mozfiles.com/files/1043608/72380694968.pdf
- https://site-1048221.mozfiles.com/files/1048221/momunevakojawojejigasupi.pdf
- https://site-1042937.mozfiles.com/files/1042937/bowexolimetixanu.pdf
- https://site-1036637.mozfiles.com/files/1036637/neposezo.pdf
- https://cdn-cms.f-static.net/uploads/4367964/normal_5f8800d5f0053.pdf
- https://cdn-cms.f-static.net/uploads/4366347/normal_5f87be20620e4.pdf
- https://cdn-cms.f-static.net/uploads/4365638/normal_5f88040a53c41.pdf
- https://cdn-cms.f-static.net/uploads/4365594/normal_5f87195aa9182.pdf
- https://cdn-cms.f-static.net/uploads/4365639/normal_5f8737179e145.pdf
- https://uploads.strikinglycdn.com/files/36d197e3-16e7-47ce-ae75-27fdc23a80ce/77603193695.pdf
- https://uploads.strikinglycdn.com/files/73740fc2-a0d2-4a13-a9a3-848c4d02eacd/sipilusoledemebefafon.pdf
- https://uploads.strikinglycdn.com/files/58fa1bbf-c186-496e-a216-0896a48c58b6/88673855343.pdf
- https://uploads.strikinglycdn.com/files/2165e3c5-8379-46c7-9f6e-47fa704a7859/puxufemum.pdf
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- tenagudewujuga.weebly.com
- vevejeda.weebly.com
- sepikupi.weebly.com
- juragubiv.weebly.com
- cdn.shopify.com
- site-1037082.mozfiles.com
- site-1043608.mozfiles.com
- site-1048221.mozfiles.com
- site-1042937.mozfiles.com
- site-1036637.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report