MALICIOUS — e680c1fcd1be.pdf
MALICIOUS — e680c1fcd1be.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
90ad32fd011879b8a41a8676814e5559d8cb1c550edb62338e988278ea2bd898 - SHA-1:
2a0ea19afd61a7e1e60820c743a863c48de682f6 - MD5:
16061d33f382c8f7097be4ee95f42113 - ssdeep:
768:qgGzpD8p2Voz795XZ2Q4c1gIuXv4PfuZzEK4Em1Rq1w2QkkP/n5Qve3cZ0:3GFgpj79fakgyf0zGnqckkPRQW3cZ0 - TLSH:
T13D35AEF31167DE4CB6CB5B07AEE71599A08AC34D61339BA08088B77CC87C5ED6E40661 - Submitted as: e680c1fcd1be.pdf
- File type: pdf · Size: 58002 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://tudupumodowi.weebly.com/uploads/1/3/1/4/131406798/b726ec796bb5.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=photoshop%20inverser%20noir%20et%20blanc, https://fekudumubaf.weebly.com/uploads/1/3/2/6/132681201/lilitifaxifasesijex.pdf, https://tudupumodowi.weebly.com/uploads/1/3/1/4/131406798/b726ec796bb5.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=photoshop%20inverser%20noir%20et%20blanc
- https://fekudumubaf.weebly.com/uploads/1/3/2/6/132681201/lilitifaxifasesijex.pdf
- https://tudupumodowi.weebly.com/uploads/1/3/1/4/131406798/b726ec796bb5.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/987b21c6b.pdf
- https://uploads.strikinglycdn.com/files/3d5c5fba-e791-4981-af36-d463769bafa3/tufonanotexojud.pdf
- https://uploads.strikinglycdn.com/files/5834f02c-9ec0-432c-b428-7805f79c5c5f/gorajanonukabaviw.pdf
- https://uploads.strikinglycdn.com/files/0eebe1e8-0647-441c-a8e0-ab5c31cea4da/78779888272.pdf
- https://uploads.strikinglycdn.com/files/eeb5529a-1ca5-4a8c-b8e6-c8372168064e/zebuninigesezuzibeliwe.pdf
- https://uploads.strikinglycdn.com/files/e47d1a1b-0487-46e2-83f3-bb51ac1290bf/pabaxugedegadalerixapesi.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/4096223.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/8925184.pdf
- https://povutepumik.weebly.com/uploads/1/3/2/7/132741486/lejegumonivixaro.pdf
- https://uploads.strikinglycdn.com/files/e1b3e9b5-ced5-4efd-8384-51c747205bde/46273233192.pdf
- https://uploads.strikinglycdn.com/files/8136cfa1-07da-456b-914e-22b6d5c8346a/76459900642.pdf
- https://uploads.strikinglycdn.com/files/8e495bb6-4883-4278-8649-940f84298a76/13433374265.pdf
- https://uploads.strikinglycdn.com/files/ffd6fbfa-a11a-4dd0-9134-7973a155e441/bomel.pdf
- https://uploads.strikinglycdn.com/files/d846a5d4-888b-4672-899d-ded1b6701d1c/24843702019.pdf
- https://site-1036655.mozfiles.com/files/1036655/95493683069.pdf
- https://site-1043705.mozfiles.com/files/1043705/zawuvotedowisufoxunodoliw.pdf
- https://site-1048490.mozfiles.com/files/1048490/transfer_letter_sample.pdf
- https://site-1038884.mozfiles.com/files/1038884/8926691444.pdf
- https://site-1042284.mozfiles.com/files/1042284/84704148839.pdf
- https://site-1038477.mozfiles.com/files/1038477/27124176053.pdf
- https://site-1048275.mozfiles.com/files/1048275/41226365209.pdf
- https://site-1043134.mozfiles.com/files/1043134/51547611446.pdf
Embedded domains
- cctraff.ru
- fekudumubaf.weebly.com
- tudupumodowi.weebly.com
- gimejexoxixaza.weebly.com
- uploads.strikinglycdn.com
- tavumake.weebly.com
- vuxozajuje.weebly.com
- povutepumik.weebly.com
- site-1036655.mozfiles.com
- site-1043705.mozfiles.com
- site-1048490.mozfiles.com
- site-1038884.mozfiles.com
- site-1042284.mozfiles.com
- site-1038477.mozfiles.com
- site-1048275.mozfiles.com
- site-1043134.mozfiles.com
- site-1044066.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report