MALICIOUS — e62242fefe.pdf
MALICIOUS — e62242fefe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 1 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
86ea0379a8d35c6398c08cdd9c9430877d1103930b9850a23114b4ac37d2c4e4 - SHA-1:
17e3dc475d2f0f9feeeae16f20ed59c0ee04a848 - MD5:
1def0d4f0575a708744c932c5d4c6c04 - ssdeep:
768:7gGzpD9pLV2uYRPPNIFL7+mzyeqQnlqQeagUH+mqARm6qjHr2:EGFZpvyQ4Qe/UeQPy2 - TLSH:
T13B317CF30097ED8C3A8E6B035EAB01AD659EC3CD51369390459C666CE47CAAD7F10B41 - Submitted as: e62242fefe.pdf
- File type: pdf · Size: 39319 bytes
- Verdict: malicious (71/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://tavumake.weebly.com/uploads/1/3/2/7/132740551/38c349888bb2ad.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=novela%20de%20reina%20de%20corazones%20capitul, https://seririgikum.weebly.com/uploads/1/3/0/7/130739922/10196.pdf, https://tavumake.weebly.com/uploads/1/3/2/7/132740551/38c349888bb2ad.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=novela%20de%20reina%20de%20corazones%20capitul
- https://seririgikum.weebly.com/uploads/1/3/0/7/130739922/10196.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/38c349888bb2ad.pdf
- https://debasomi.weebly.com/uploads/1/3/0/7/130739769/81fc7.pdf
- https://tejigenunonim.weebly.com/uploads/1/3/0/8/130813632/xebopuviban.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/winepogor.pdf
- https://cdn.shopify.com/s/files/1/0482/4406/4408/files/red_poppy_tea_and_hookah.pdf
- https://cdn.shopify.com/s/files/1/0266/9704/0063/files/63300684098.pdf
- https://cdn.shopify.com/s/files/1/0480/5551/7348/files/brigmore_witches_trophy_guide.pdf
- https://cdn.shopify.com/s/files/1/0488/2310/7749/files/thermaltake_versa_n21_how_to_remove_front_panel.pdf
- https://uploads.strikinglycdn.com/files/073bb18e-d309-4c97-bbbd-c418138056c4/40530831129.pdf
- https://uploads.strikinglycdn.com/files/34296f06-a1ae-41f8-8d78-b6c1aa0e5534/bogadiwojajosogurefetika.pdf
- https://uploads.strikinglycdn.com/files/59bfc4a2-763d-4fec-ae5b-1743cf0a453b/wigulobet.pdf
- https://uploads.strikinglycdn.com/files/32a96cb1-1fc7-4815-8954-add725a0bf5f/95399198313.pdf
- https://uploads.strikinglycdn.com/files/ca3040ab-6a29-4fb5-a8ad-bbf3fdd8525a/48261598422.pdf
- https://site-1044103.mozfiles.com/files/1044103/xonajakadik.pdf
- https://site-1039484.mozfiles.com/files/1039484/zitisulat.pdf
- https://site-1038943.mozfiles.com/files/1038943/daxokakedokewonijiwo.pdf
- https://site-1048185.mozfiles.com/files/1048185/suxepavalevirevaf.pdf
- https://cdn.shopify.com/s/files/1/0434/7835/2022/files/mtg_arena_limited_schedule.pdf
- https://cdn.shopify.com/s/files/1/0434/6049/3474/files/whatcom_middle_school_yearbook.pdf
- https://cdn.shopify.com/s/files/1/0482/8761/3096/files/jivigivipozujakixajigig.pdf
- https://cdn-cms.f-static.net/uploads/4366311/normal_5f876b6fda941.pdf
- https://cdn-cms.f-static.net/uploads/4366357/normal_5f875a8eac02f.pdf
- https://cdn-cms.f-static.net/uploads/4367687/normal_5f87d375874f3.pdf
Embedded domains
- gettraff.ru
- seririgikum.weebly.com
- tavumake.weebly.com
- debasomi.weebly.com
- tejigenunonim.weebly.com
- zoxuzuxebexot.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1044103.mozfiles.com
- site-1039484.mozfiles.com
- site-1038943.mozfiles.com
- site-1048185.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report