MALICIOUS — 6fc4b4229a63b.pdf
MALICIOUS — 6fc4b4229a63b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 1 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7b3286db24f8aa91bbf95bc2814b61c168cde4c74185ed10a7ba66749c7982e5 - SHA-1:
8c9e7e202f874169df8d725ee352a0ca5833edf4 - MD5:
07faa396b3b6df3fc55c1e1a2e03d7c4 - ssdeep:
768:WgGzpDgeARSQFVT9Mm42LaokxoG00U3ijjcwOnyJmF:DGF0eGkX0GcwOyJmF - TLSH:
T196305CF31097EC8CBB8B9B53ADE7115A558AC7486136D7A0488CAB2CC47C5BC7E50950 - Submitted as: 6fc4b4229a63b.pdf
- File type: pdf · Size: 35954 bytes
- Verdict: malicious (71/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/0cbd7f35736ab.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=ge%20fanuc%20plc%20manual, https://folanejo.weebly.com/uploads/1/3/0/7/130776558/ab8c8e561a50a3.pdf, https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/0cbd7f35736ab.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=ge%20fanuc%20plc%20manual
- https://folanejo.weebly.com/uploads/1/3/0/7/130776558/ab8c8e561a50a3.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/0cbd7f35736ab.pdf
- https://dagigokes.weebly.com/uploads/1/3/0/7/130739756/pusonux.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/bfcfaa.pdf
- https://cdn-cms.f-static.net/uploads/4369332/normal_5f889d12ec609.pdf
- https://cdn-cms.f-static.net/uploads/4365586/normal_5f870bf1dd326.pdf
- https://cdn-cms.f-static.net/uploads/4368982/normal_5f88c7f872006.pdf
- https://cdn-cms.f-static.net/uploads/4368230/normal_5f8905a951334.pdf
- https://cdn-cms.f-static.net/uploads/4369323/normal_5f882bbc8d413.pdf
- https://site-1040141.mozfiles.com/files/1040141/kuxirulemolexogukap.pdf
- https://site-1036702.mozfiles.com/files/1036702/22250345748.pdf
- https://cdn.shopify.com/s/files/1/0501/4667/2805/files/the_impossible_quiz_31.pdf
- https://cdn.shopify.com/s/files/1/0429/5891/3689/files/apalachee_beekeepers_association.pdf
- https://cdn.shopify.com/s/files/1/0497/7478/8769/files/the_sun_also_rises_quotes.pdf
- https://cdn.shopify.com/s/files/1/0435/3474/5760/files/unit_8_level_f_vocab_answers_choosing_the_right_word.pdf
- https://cdn.shopify.com/s/files/1/0268/7418/3853/files/vulowekuronezirezusosi.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/09b03b.pdf
- https://vodipewelo.weebly.com/uploads/1/3/1/6/131637384/sunutubevitadobux.pdf
- https://zuxuzesis.weebly.com/uploads/1/3/1/4/131438019/xekev.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/bigunurusipota_vovavubavuw_malolipesafa.pdf
- https://cdn-cms.f-static.net/uploads/4367947/normal_5f88624192689.pdf
- https://cdn-cms.f-static.net/uploads/4365576/normal_5f87088728373.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- folanejo.weebly.com
- jakedekokobara.weebly.com
- dagigokes.weebly.com
- tavumake.weebly.com
- cdn-cms.f-static.net
- site-1040141.mozfiles.com
- site-1036702.mozfiles.com
- cdn.shopify.com
- jatorogerujew.weebly.com
- vodipewelo.weebly.com
- zuxuzesis.weebly.com
- keniwuki.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report