MALICIOUS — vesaniweju-fegib.pdf
MALICIOUS — vesaniweju-fegib.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8592f1b1f6b528ca038f4efb733b670f778cb86f735ea5a2329f44cfefcf8041 - SHA-1:
7a76c6d53e43a33480547e97b6c722145e0fad57 - MD5:
ecc10e984dc76ae1fce8de41d96fc098 - ssdeep:
768:4gGzpD3eKc+i7Wz84zdAG8ar7Nb5CHwD3SqWknChffcrSXHkCTj7hWvkxf:VGFrelqAGVNtCQJnChseXHkCP7h8kxf - TLSH:
T1ED339EF7409BED8C7A8BAB13ADAB1166914EC74CA136E7505088776DC4BC6BDBE10C10 - Submitted as: vesaniweju-fegib.pdf
- File type: pdf · Size: 51856 bytes
- Verdict: malicious (75/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/tiladejonu.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=credit%20secrets%20book%20reviews, https://uploads.strikinglycdn.com/files/b3cf351e-326e-43b8-84ea-fcd15965e63d/rimolubewuzune.pdf, https://uploads.strikinglycdn.com/files/a3c3c3ba-4382-40a1-93bc-08fcbac1d3e0/72562702616.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=credit%20secrets%20book%20reviews
- https://uploads.strikinglycdn.com/files/b3cf351e-326e-43b8-84ea-fcd15965e63d/rimolubewuzune.pdf
- https://uploads.strikinglycdn.com/files/a3c3c3ba-4382-40a1-93bc-08fcbac1d3e0/72562702616.pdf
- https://uploads.strikinglycdn.com/files/f0751f59-dd35-4429-9e6e-0ca303c7ade5/6556658519.pdf
- https://uploads.strikinglycdn.com/files/9bf972b9-949e-4d6c-bb2e-dcbd6a3a016c/29964611134.pdf
- https://uploads.strikinglycdn.com/files/38e5ace4-d824-4f42-bec6-5af0a10389b8/19588652747.pdf
- https://uploads.strikinglycdn.com/files/9e612b2e-04fe-482e-af5d-136d1519c952/rejogud.pdf
- https://uploads.strikinglycdn.com/files/68083103-e833-48bd-88cc-37b6e52da998/12269154428.pdf
- https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/8628557.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/tiladejonu.pdf
- https://fekudumubaf.weebly.com/uploads/1/3/2/6/132681201/3321595.pdf
- https://cdn-cms.f-static.net/uploads/4372080/normal_5f887c1beb92f.pdf
- https://cdn-cms.f-static.net/uploads/4368469/normal_5f8a5d858ffdb.pdf
- https://cdn-cms.f-static.net/uploads/4368251/normal_5f880530b7850.pdf
- https://cdn-cms.f-static.net/uploads/4372707/normal_5f894e632ef7b.pdf
- https://cdn-cms.f-static.net/uploads/4366045/normal_5f873c866cbcf.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/mifenadubuj-gemaz-biresilogi-xalewuzejo.pdf
- https://bilewobadazape.weebly.com/uploads/1/3/2/6/132695578/lepafo_xufivajetafobom.pdf
- https://xifobosakup.weebly.com/uploads/1/3/2/8/132815359/d819ed4.pdf
- https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/69cda82938.pdf
- https://uploads.strikinglycdn.com/files/24825d2d-b906-44e3-b4f6-75797aa35d47/vanabutulo.pdf
- https://uploads.strikinglycdn.com/files/c1671adc-4c20-40cd-ac7f-ec22037aa32b/lavuwitosudojajaw.pdf
- https://uploads.strikinglycdn.com/files/e2c5df76-7a4d-41ff-bfe7-bb42de9eca4e/64571446966.pdf
- https://uploads.strikinglycdn.com/files/7ebebfd4-6ac4-4943-92cc-5d0eb7691aa2/95930219989.pdf
- https://uploads.strikinglycdn.com/files/28ab207e-f3a7-4989-a4dd-3499883c0086/39456655636.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- tivakoxidedopa.weebly.com
- guwomenod.weebly.com
- fekudumubaf.weebly.com
- cdn-cms.f-static.net
- wepugimi.weebly.com
- bilewobadazape.weebly.com
- xifobosakup.weebly.com
- juragubiv.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- F:\[;22
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report