MALICIOUS — 76ae4d9e.pdf
MALICIOUS — 76ae4d9e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8261db82fd42849f96820a8857dd4f13302df8ac541442a4ae0a9c1835f08c44 - SHA-1:
b84d7803809d387d1bf5d7fb4adb821af18c4ccd - MD5:
7e160aa0e64b11de6432a64688e0cf2f - ssdeep:
768:YgGzpDKplzf/q5rFHG9g8MqOa+5a1jmvWvcWGRwfHV1NBAx+rH+hfaziA:1GFuplzf/q0ZIvWvc2AxHaziA - TLSH:
T1D7339EF30097EC4D768F5B039EB32299604AD78DA0329761459C7B2CD4BC6ED7E01951 - Submitted as: 76ae4d9e.pdf
- File type: pdf · Size: 51892 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://damijuvik.weebly.com/uploads/1/3/1/3/131381376/duviviligazofaz.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=fsa%20math%20practice%206th%20grade%20pdf, https://uploads.strikinglycdn.com/files/544c8c2c-55cc-40f4-9ec8-47ffb89382f5/notik.pdf, https://uploads.strikinglycdn.com/files/091de313-3d65-49e2-9f17-20364a4edb6e/59786472069.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=fsa%20math%20practice%206th%20grade%20pdf
- https://uploads.strikinglycdn.com/files/544c8c2c-55cc-40f4-9ec8-47ffb89382f5/notik.pdf
- https://uploads.strikinglycdn.com/files/091de313-3d65-49e2-9f17-20364a4edb6e/59786472069.pdf
- https://uploads.strikinglycdn.com/files/82cb2189-1f88-4f54-9280-578a71735f75/xadigusaluwumomileko.pdf
- https://cdn-cms.f-static.net/uploads/4368238/normal_5f89cf50be495.pdf
- https://wosezobar.weebly.com/uploads/1/3/1/8/131856012/6711581.pdf
- https://fotejisatowonu.weebly.com/uploads/1/3/2/3/132302873/zegoli_denemoji.pdf
- https://damijuvik.weebly.com/uploads/1/3/1/3/131381376/duviviligazofaz.pdf
- https://cdn.shopify.com/s/files/1/0501/7098/6658/files/desajil.pdf
- https://cdn.shopify.com/s/files/1/0430/0354/3715/files/emg_ncs_near_me.pdf
- https://cdn.shopify.com/s/files/1/0433/5111/3887/files/homedale_high_school_homedale_id.pdf
- https://cdn.shopify.com/s/files/1/0483/9053/7373/files/derecho_individual_del_trabajo_unam.pdf
- https://cdn.shopify.com/s/files/1/0496/2825/0276/files/zejunekoke.pdf
- https://uploads.strikinglycdn.com/files/24c9bbf0-536c-4f19-a9e6-caed6ae1a3b9/raziluxe.pdf
- https://uploads.strikinglycdn.com/files/8c778820-e916-41a7-9364-d096a24b2aca/2782375224.pdf
- https://uploads.strikinglycdn.com/files/2c7398d4-51b7-482f-85ae-ac76e986c6b9/remington_1858_new_army.pdf
- https://uploads.strikinglycdn.com/files/3a3b1254-9bd1-4ba1-a36c-35254fb10b95/4816853184.pdf
- https://nitiruminaxodax.weebly.com/uploads/1/3/0/7/130738633/3678353.pdf
- https://sibakixode.weebly.com/uploads/1/3/2/8/132814768/movav.pdf
- https://vejuvofarazaxar.weebly.com/uploads/1/3/4/3/134355137/setuxadubi_lerafab_zebipavuv_tekeg.pdf
- https://vodipewelo.weebly.com/uploads/1/3/1/6/131637384/270f5c.pdf
- https://genamimiwovem.weebly.com/uploads/1/3/1/6/131636881/41f490e289.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- wosezobar.weebly.com
- fotejisatowonu.weebly.com
- damijuvik.weebly.com
- cdn.shopify.com
- nitiruminaxodax.weebly.com
- sibakixode.weebly.com
- vejuvofarazaxar.weebly.com
- vodipewelo.weebly.com
- genamimiwovem.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report