MALICIOUS — fanakub.pdf
MALICIOUS — fanakub.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a0b336c4e38811a4db4202d7de24e402aabd14e651bea697f5fd1aa42381f1f8 - SHA-1:
624e827f606a02d0576ca3c6e848d955363be75f - MD5:
9506a3634ec17131ef3cb266769af290 - ssdeep:
768:d0gGzpDypoc3L8dFaVJYSCDLkzezocTWIPovpBrVVBWX8AIaL+a4rHdgneFJDUWu:7GFmpaa0zDLkqo2WfkX3IMM9gnefV7je - TLSH:
T112328DF310A3FD8C7B4BEB17ADA61199648AC3896133A7A045C86B2CD07C5FE3E00651 - Submitted as: fanakub.pdf
- File type: pdf · Size: 45544 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jeponiruwapin.weebly.com/uploads/1/3/0/7/130776483/resimogapukizudel.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=illustrated%20study%20guide%20for%20the%20nclex-rn%20exam%209th%20edition, https://cdn-cms.f-static.net/uploads/4366003/normal_5f8700830dfa7.pdf, https://cdn-cms.f-static.net/uploads/4365570/normal_5f87024171c72.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=illustrated%20study%20guide%20for%20the%20nclex-rn%20exam%209th%20edition
- https://cdn-cms.f-static.net/uploads/4366003/normal_5f8700830dfa7.pdf
- https://cdn-cms.f-static.net/uploads/4365570/normal_5f87024171c72.pdf
- https://cdn-cms.f-static.net/uploads/4367959/normal_5f87dd79489dc.pdf
- https://cdn-cms.f-static.net/uploads/4366003/normal_5f8749c4eff55.pdf
- https://cdn-cms.f-static.net/uploads/4366014/normal_5f87f5367ed75.pdf
- https://winomumamo.weebly.com/uploads/1/3/1/0/131070375/1708563.pdf
- https://jeponiruwapin.weebly.com/uploads/1/3/0/7/130776483/resimogapukizudel.pdf
- https://uploads.strikinglycdn.com/files/2e16a108-5e03-4500-820a-e9801af16424/redexobapisexojag.pdf
- https://uploads.strikinglycdn.com/files/5c60456f-dc89-4df6-9a8f-bfe3277c4447/likuxajexofuzopuwilak.pdf
- https://uploads.strikinglycdn.com/files/3caffd56-b0aa-4484-946f-f2cef98810d4/73369137967.pdf
- https://uploads.strikinglycdn.com/files/1d55fbac-66e8-4c82-afac-acdc69d170f2/bumukor.pdf
- https://uploads.strikinglycdn.com/files/8dea6b5b-d859-4f36-a23c-b5b1faa74b08/41091302166.pdf
- https://jeponiruwapin.weebly.com/uploads/1/3/0/7/130776483/timafu-wevaxanarewo.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/daxurugut.pdf
- https://tekegalesi.weebly.com/uploads/1/3/0/7/130740489/4d869f1c.pdf
- https://cdn.shopify.com/s/files/1/0434/9231/1206/files/58402161399.pdf
- https://cdn.shopify.com/s/files/1/0440/6847/0936/files/nimaf.pdf
- https://cdn.shopify.com/s/files/1/0481/5519/7593/files/freak_the_mighty_worksheets_activities.pdf
- https://cdn.shopify.com/s/files/1/0437/9443/2161/files/insula_orientalis_dq11.pdf
- https://cdn.shopify.com/s/files/1/0480/8209/2196/files/sisanezamujolo.pdf
- https://site-1040869.mozfiles.com/files/1040869/susan_sontag_illness_as_a_metaphor.pdf
- https://site-1044238.mozfiles.com/files/1044238/handbook_of_development_economics_vol_1.pdf
- https://site-1039674.mozfiles.com/files/1039674/korajujavaguro.pdf
- https://site-1043205.mozfiles.com/files/1043205/84502699459.pdf
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- winomumamo.weebly.com
- jeponiruwapin.weebly.com
- uploads.strikinglycdn.com
- tavumake.weebly.com
- tekegalesi.weebly.com
- cdn.shopify.com
- site-1040869.mozfiles.com
- site-1044238.mozfiles.com
- site-1039674.mozfiles.com
- site-1043205.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report