MALICIOUS — 7973492.pdf
MALICIOUS — 7973492.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7557374c2da406e00e2717c5ec063576211c92a5b6fc6dacb95a6f93244500b5 - SHA-1:
de0ba9ba023ded1f4331ca7d1bd84846bd270408 - MD5:
9b8979382aedb93e2aaa9b65fd095f48 - ssdeep:
1536:aGFVpc+/TBPRMzhL2jZPc0U6KVb2F0ZvIlNQYqwLVcwWuBarJRxhw86Mj:DFVpc+/TBMLP0U2aATQVwjBaVRxhwc - TLSH:
T1FF3AC0E35493DC8D79CA8F836DA71069318AD7896232DA9444CCAB7CC47CBBD7D00A91 - Submitted as: 7973492.pdf
- File type: pdf · Size: 95571 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/ramugimexixepaba.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=ram%20raksha%20stotra%20pdf, https://uploads.strikinglycdn.com/files/832a4325-0d8b-4fc9-877a-229075713656/kutomaxugadurirofokidezub.pdf, https://uploads.strikinglycdn.com/files/2de10b34-ba0b-4c26-9801-dfd3e286a27d/noxuluve.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=ram%20raksha%20stotra%20pdf
- https://uploads.strikinglycdn.com/files/832a4325-0d8b-4fc9-877a-229075713656/kutomaxugadurirofokidezub.pdf
- https://uploads.strikinglycdn.com/files/2de10b34-ba0b-4c26-9801-dfd3e286a27d/noxuluve.pdf
- https://uploads.strikinglycdn.com/files/38f2ad2f-ca93-4b7c-81b5-3c358e5afa54/gulujikelipekexiwiwob.pdf
- https://uploads.strikinglycdn.com/files/f97d285e-101d-4cf5-b0b4-7109ae9500e4/newasezid.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/ramugimexixepaba.pdf
- https://lagukekejase.weebly.com/uploads/1/3/0/8/130815031/guwaderenel_linufevoroxaf_guzafosone_jodavoxiveb.pdf
- https://jobubati.weebly.com/uploads/1/3/1/4/131453688/dd715.pdf
- https://lodirunesu.weebly.com/uploads/1/3/0/8/130874391/zapanexise.pdf
- https://uploads.strikinglycdn.com/files/d06881bb-831d-4156-a063-a49d0c6877b8/3111086337.pdf
- https://uploads.strikinglycdn.com/files/bb9ec101-bca8-490c-82d0-e1475c1fab30/kikab.pdf
- https://uploads.strikinglycdn.com/files/cb2c8eff-aa15-4e6b-8b0a-87fbb866b92c/fulenowexokenut.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/nasugajujufaso-nawaripalu-zazovez-napidoduri.pdf
- https://babinekisifuve.weebly.com/uploads/1/3/2/6/132696104/tojikogidulusani.pdf
- https://mabanopovofed.weebly.com/uploads/1/3/1/4/131453130/9442939.pdf
- https://redunexodozik.weebly.com/uploads/1/3/0/8/130814050/wulukobukiguxufulev.pdf
- https://lajojixuvoporor.weebly.com/uploads/1/3/0/7/130738555/4726015.pdf
- https://wesoxiworikezux.weebly.com/uploads/1/3/1/3/131380467/lesukomugojelez-vazari-xafokafiru.pdf
- https://mamexobupelo.weebly.com/uploads/1/3/1/3/131383482/558f72942e7b60c.pdf
- https://gurigibafex.weebly.com/uploads/1/3/0/7/130739571/rumalax-gixasufusez-labunajigom-popado.pdf
- https://cdn.shopify.com/s/files/1/0434/4119/3127/files/the_interpreter_of_maladies_audiobook.pdf
- https://cdn.shopify.com/s/files/1/0432/8377/5643/files/jazz_theory_book_levine_download.pdf
- https://cdn.shopify.com/s/files/1/0432/7378/1408/files/glass_display_dome.pdf
- https://cdn.shopify.com/s/files/1/0483/7113/8709/files/alexa_sxt_manual.pdf
- https://cdn.shopify.com/s/files/1/0437/6110/7096/files/mewokutevupexarofebuv.pdf
Embedded domains
- gettraff.ru
- rl.tk
- uploads.strikinglycdn.com
- guwomenod.weebly.com
- lagukekejase.weebly.com
- jobubati.weebly.com
- lodirunesu.weebly.com
- tavumake.weebly.com
- babinekisifuve.weebly.com
- mabanopovofed.weebly.com
- redunexodozik.weebly.com
- lajojixuvoporor.weebly.com
- wesoxiworikezux.weebly.com
- mamexobupelo.weebly.com
- gurigibafex.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report