MALICIOUS — afb317b1cced83.pdf
MALICIOUS — afb317b1cced83.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7c04b114188f7adc26cff5c8ae3d979c93a079f8d28db08a347b1213342cef75 - SHA-1:
38362866d3f8cbb2281b377ecae430170af00e62 - MD5:
7e113af0e1414fb370630c4072f0c935 - ssdeep:
768:BgGzpD6OpfRAh1ha82nV/pMwtCsjJfo7OXr7MKUKiB/9vLXQb51EGXZ:yGFfpqaosjJf8sjUB/9vLAbzEGXZ - TLSH:
T1EC307BF340A7ED8C7BCB9B13ACAA15AA2489D7896037975048C8676DC47C2FD7F01860 - Submitted as: afb317b1cced83.pdf
- File type: pdf · Size: 39119 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://wesoxiworikezux.weebly.com/uploads/1/3/1/3/131380467/vodovofigumeji.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=sur%20la%20tamise%20mots%20fleches, https://zukamukenipebo.weebly.com/uploads/1/3/1/3/131380388/9216142.pdf, https://bijifejutumaxob.weebly.com/uploads/1/3/1/3/131381781/10f8c.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=sur%20la%20tamise%20mots%20fleches
- https://zukamukenipebo.weebly.com/uploads/1/3/1/3/131380388/9216142.pdf
- https://bijifejutumaxob.weebly.com/uploads/1/3/1/3/131381781/10f8c.pdf
- https://wesoxiworikezux.weebly.com/uploads/1/3/1/3/131380467/vodovofigumeji.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f86fe5bc871b.pdf
- https://cdn-cms.f-static.net/uploads/4366055/normal_5f86ffce983bc.pdf
- https://cdn-cms.f-static.net/uploads/4368506/normal_5f87c3a47eb08.pdf
- https://cdn-cms.f-static.net/uploads/4368781/normal_5f87e09c6354d.pdf
- https://fupexorugukemig.weebly.com/uploads/1/3/0/8/130814763/depasepebiwijagumi.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/4d5351fbb209c0.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/vunidixeviro_xitosujitupile_kadape.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/mofep.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/4867245.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/09b03b.pdf
- https://nosekuge.weebly.com/uploads/1/3/2/7/132740467/bonogisupu.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/sixukejomiwewanage.pdf
- https://nanorobudilason.weebly.com/uploads/1/3/0/7/130775181/pumupipi.pdf
- https://site-1043485.mozfiles.com/files/1043485/63862336752.pdf
- https://site-1039907.mozfiles.com/files/1039907/31745825568.pdf
- https://site-1039535.mozfiles.com/files/1039535/98779430074.pdf
- https://cdn.shopify.com/s/files/1/0440/4002/8325/files/war_of_the_five_kings.pdf
- https://cdn.shopify.com/s/files/1/0484/0636/4317/files/cher_just_like_jesse_james_live.pdf
- https://cdn.shopify.com/s/files/1/0481/4598/9783/files/how_to_train_your_dragon_book_of_dragons_full_movie.pdf
- https://cdn.shopify.com/s/files/1/0483/5252/6489/files/palm_desert_library_phone_number.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- zukamukenipebo.weebly.com
- bijifejutumaxob.weebly.com
- wesoxiworikezux.weebly.com
- cdn-cms.f-static.net
- fupexorugukemig.weebly.com
- zoxuzuxebexot.weebly.com
- bedizegoresupa.weebly.com
- guwomenod.weebly.com
- gimejexoxixaza.weebly.com
- jatorogerujew.weebly.com
- nosekuge.weebly.com
- mogilifus.weebly.com
- nanorobudilason.weebly.com
- site-1043485.mozfiles.com
- site-1039907.mozfiles.com
- site-1039535.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report