MALICIOUS — 8293563.pdf
MALICIOUS — 8293563.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7a2aac6691f6613afd7d2693a2c1ba8dadcd8fc0196d96f859178c8508285ed8 - SHA-1:
fb1c859b2bc6583e1e9fa6ca9b7b3891c6ab1ccf - MD5:
0f3965c0b421db8775e76d9279e463d8 - ssdeep:
768:0gGzpDlpe7nTxxhzsfX9aCL9bOcjPlJeqDo1n292bzNWAJyxj/rzicmb:BGFhp2xhwbZz3aO2bzNWAo5rWPb - TLSH:
T169339EF3646BED4C7A86DB03A9E71059615AC78C323397B05488BB2CC47C5FCAE01A61 - Submitted as: 8293563.pdf
- File type: pdf · Size: 52124 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/e9ff54.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=voi%20che%20sapete%20paroles, https://xazapadikud.weebly.com/uploads/1/3/1/8/131871762/546312.pdf, https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/e9ff54.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=voi%20che%20sapete%20paroles
- https://xazapadikud.weebly.com/uploads/1/3/1/8/131871762/546312.pdf
- https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/e9ff54.pdf
- https://wepeweguwerixum.weebly.com/uploads/1/3/1/8/131856135/nekukomu-popotumon-renubadit.pdf
- https://tekegalesi.weebly.com/uploads/1/3/0/7/130740489/6023182.pdf
- https://uploads.strikinglycdn.com/files/efb34cf7-3756-45e3-b614-8145052c4231/sudodo.pdf
- https://uploads.strikinglycdn.com/files/bbadadd0-cde3-4b38-ab7f-0098eb01ccb6/mapamoxanimal.pdf
- https://uploads.strikinglycdn.com/files/72c36fd6-9664-498e-8372-d198b584e361/mukuzufedeparazikikadewix.pdf
- https://uploads.strikinglycdn.com/files/725d2535-615e-4402-a846-7721238fc5ee/maxamexexofedeludumijadi.pdf
- https://uploads.strikinglycdn.com/files/46be5003-2bf5-4573-a15e-19d8f60d7d61/12635527912.pdf
- https://uploads.strikinglycdn.com/files/3982f03a-32db-44d9-a88d-31b902038f71/95236322506.pdf
- https://uploads.strikinglycdn.com/files/3c1f82fd-72b9-4f0e-b7d1-57d7570e75d7/kelovubekaxoj.pdf
- https://cdn.shopify.com/s/files/1/0431/8009/7702/files/pcsx2_mac_tutorial.pdf
- https://cdn.shopify.com/s/files/1/0484/3565/8906/files/88060561341.pdf
- https://site-1043611.mozfiles.com/files/1043611/lalofif.pdf
- https://site-1039922.mozfiles.com/files/1039922/xopumewemakunuki.pdf
- https://site-1036781.mozfiles.com/files/1036781/gujozeduvotilifirakuvapo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- xazapadikud.weebly.com
- fodezamu.weebly.com
- wepeweguwerixum.weebly.com
- tekegalesi.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1043611.mozfiles.com
- site-1039922.mozfiles.com
- site-1036781.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report