MALICIOUS — 8919482.pdf
MALICIOUS — 8919482.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
722ab411b5a4edeee11585ede410b8e8e5e7fbece766846e8a9cc0be27daab66 - SHA-1:
527ed0c852230d3cbe7833235973c93342868936 - MD5:
2c2dba1a68186e0f8b5f07ca7349d148 - ssdeep:
1536:TGFdpa7N9oPxhVzFXVjAX98Gbsp9QvFP01cIAOUh2AEtOqM38C5dFu:iFdpa7ktFXk98msvKoDAOFAEtG38CVu - TLSH:
T11D35BFF34297DC4C6A8A9B139D6A2196248BD7CDA03297E415DC737CC0BC3EDAE41921 - Submitted as: 8919482.pdf
- File type: pdf · Size: 58254 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://giwakatunu.weebly.com/uploads/1/3/1/4/131437107/woxesegela.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=manual%20nissan%20sentra%20b15%20pdf, https://kuwofepex.weebly.com/uploads/1/3/2/7/132740654/rimawutevotom_bubiragageka.pdf, https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/lukinabowib-zazepuwilef.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=manual%20nissan%20sentra%20b15%20pdf
- https://kuwofepex.weebly.com/uploads/1/3/2/7/132740654/rimawutevotom_bubiragageka.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/lukinabowib-zazepuwilef.pdf
- https://vuxilimibipemop.weebly.com/uploads/1/3/1/4/131453056/4480016.pdf
- https://giwakatunu.weebly.com/uploads/1/3/1/4/131437107/woxesegela.pdf
- https://zafozudakajadev.weebly.com/uploads/1/3/0/8/130814863/b628c54eef4e3.pdf
- https://cdn-cms.f-static.net/uploads/4367952/normal_5f878e7445cd8.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/1109957.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/xekena.pdf
- https://kinojapi.weebly.com/uploads/1/3/2/3/132302846/3106b2b.pdf
- https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/9506eb3ef.pdf
- https://nanorobudilason.weebly.com/uploads/1/3/0/7/130775181/savowipobow.pdf
- https://cdn-cms.f-static.net/uploads/4373259/normal_5f88c5164f913.pdf
- https://cdn-cms.f-static.net/uploads/4368762/normal_5f87a4f98a915.pdf
- https://cdn-cms.f-static.net/uploads/4365638/normal_5f86fada5b5a8.pdf
- https://cdn-cms.f-static.net/uploads/4365613/normal_5f86f651ce858.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- kuwofepex.weebly.com
- vozunutav.weebly.com
- vuxilimibipemop.weebly.com
- giwakatunu.weebly.com
- zafozudakajadev.weebly.com
- cdn-cms.f-static.net
- bedizegoresupa.weebly.com
- xojerajap.weebly.com
- kinojapi.weebly.com
- vilukenuxe.weebly.com
- nanorobudilason.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report