MALICIOUS — b3ffedbda84f4c.pdf
MALICIOUS — b3ffedbda84f4c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9d10b0740a8bd004aeb29c49b9b4acb4fd44df2da92347cf2df5b64ff49a3102 - SHA-1:
55e74f01b18a646705d7e6b79a2150931bbc5ee8 - MD5:
8cc4d12c1d0000c437ea12700e3b9115 - ssdeep:
1536:AGF+puHcYsHRWmXFbtSqewpZqFRIXmfoa9:NF+puHJYRrpkdwpAnIWr - TLSH:
T18634AEF350ABED4C7E879B53ACAA25592089C749B233D7605498763CC87C6BD7F00A20 - Submitted as: b3ffedbda84f4c.pdf
- File type: pdf · Size: 53927 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://tejigenunonim.weebly.com/uploads/1/3/0/8/130813632/737298.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=inside%20hero%20joc%20pareri, https://nasinapalu.weebly.com/uploads/1/3/0/7/130739684/kujiruwug-migenojigilodu.pdf, https://tejigenunonim.weebly.com/uploads/1/3/0/8/130813632/737298.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=inside%20hero%20joc%20pareri
- https://nasinapalu.weebly.com/uploads/1/3/0/7/130739684/kujiruwug-migenojigilodu.pdf
- https://tejigenunonim.weebly.com/uploads/1/3/0/8/130813632/737298.pdf
- https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/a7b88.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/budup_muruketika_befusijago.pdf
- https://lasajiboz.weebly.com/uploads/1/3/1/3/131379041/e823f39d89218.pdf
- https://cdn-cms.f-static.net/uploads/4370068/normal_5f87fdfaf029c.pdf
- https://cdn-cms.f-static.net/uploads/4365619/normal_5f8716f95ae52.pdf
- https://cdn-cms.f-static.net/uploads/4365642/normal_5f870c61c839a.pdf
- https://cdn-cms.f-static.net/uploads/4366028/normal_5f87129fa3655.pdf
- https://cdn-cms.f-static.net/uploads/4365598/normal_5f87428b4077f.pdf
- https://cdn-cms.f-static.net/uploads/4365662/normal_5f8739175635e.pdf
- https://cdn-cms.f-static.net/uploads/4366011/normal_5f873bb9f19c7.pdf
- https://site-1037149.mozfiles.com/files/1037149/60608520240.pdf
- https://site-1038717.mozfiles.com/files/1038717/55116256776.pdf
- https://site-1038868.mozfiles.com/files/1038868/42949268286.pdf
- https://site-1038970.mozfiles.com/files/1038970/76981039834.pdf
- https://site-1040249.mozfiles.com/files/1040249/bukivufilupavemopaju.pdf
- https://uploads.strikinglycdn.com/files/7c754c7e-9ff7-48cf-9172-b55285b9d1d7/nonemunasitikoredux.pdf
- https://uploads.strikinglycdn.com/files/bf33d826-d7f0-4bc9-a74c-6dd6b694968e/tesigepijomasiguwor.pdf
- https://uploads.strikinglycdn.com/files/e686fbe5-015b-4d15-8214-b26460fd95cd/51737831029.pdf
- https://site-1042822.mozfiles.com/files/1042822/39962385684.pdf
- https://site-1044105.mozfiles.com/files/1044105/android_one_ui_dark_mode.pdf
- https://site-1042545.mozfiles.com/files/1042545/tuwefufopagemi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- nasinapalu.weebly.com
- tejigenunonim.weebly.com
- gevafitasib.weebly.com
- guwomenod.weebly.com
- lasajiboz.weebly.com
- cdn-cms.f-static.net
- site-1037149.mozfiles.com
- site-1038717.mozfiles.com
- site-1038868.mozfiles.com
- site-1038970.mozfiles.com
- site-1040249.mozfiles.com
- uploads.strikinglycdn.com
- site-1042822.mozfiles.com
- site-1044105.mozfiles.com
- site-1042545.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report