MALICIOUS — band_of_brothers_lieutenant_speirs.pdf
MALICIOUS — band_of_brothers_lieutenant_speirs.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a2175dec433f1d4dcb31906d3091fed0d253cf0a0cc6dd765dcd2d40512c677d - SHA-1:
180fc60f26fca1ebda7e471a105b83de205e2609 - MD5:
2caf0811f82f60149b47f65d50576173 - ssdeep:
768:QgGzpDtpXC9bBcVSMURjr9ED3xCO+whufzHqSMHAy7zkZ1qWzlOOeMD868:9GFJpXCp5ED3N+whubH+x7k1/lTD868 - TLSH:
T15933AEF70497EC8C7F8A9B03ADEA0569519AC38DA033872055887B7CC5FC5AD6F20951 - Submitted as: band_of_brothers_lieutenant_speirs.pdf
- File type: pdf · Size: 49689 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://wefolukozik.weebly.com/uploads/1/3/1/4/131406413/tilorekojadera_wiwukup_bevatetuxuna_rarakitida.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=band+of+brothers+lieutenant+speirs, https://uploads.strikinglycdn.com/files/12942b20-c0b2-4b98-9a39-cf1fc4323cee/tozesujejif.pdf, https://uploads.strikinglycdn.com/files/3053a0a1-0317-44f8-928c-d6d9ed8da7e2/7232444501.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=band+of+brothers+lieutenant+speirs
- https://uploads.strikinglycdn.com/files/12942b20-c0b2-4b98-9a39-cf1fc4323cee/tozesujejif.pdf
- https://uploads.strikinglycdn.com/files/3053a0a1-0317-44f8-928c-d6d9ed8da7e2/7232444501.pdf
- https://uploads.strikinglycdn.com/files/c388328d-f855-4aa7-9f1c-5ecf57d3423c/4337711516.pdf
- https://uploads.strikinglycdn.com/files/5b8dce92-6b02-46c0-8cf1-4a54cf672e3b/riwoxuzusudubimaja.pdf
- https://uploads.strikinglycdn.com/files/c024af09-afad-4cbf-918c-bbe1c0ad8b49/74080081727.pdf
- https://wefolukozik.weebly.com/uploads/1/3/1/4/131406413/tilorekojadera_wiwukup_bevatetuxuna_rarakitida.pdf
- https://ganulexotugoris.weebly.com/uploads/1/3/1/1/131164012/sosef.pdf
- https://xipunozelizu.weebly.com/uploads/1/3/1/3/131382486/cfeeee9ec3.pdf
- https://rabugotekinevod.weebly.com/uploads/1/3/1/8/131871666/2977379.pdf
- https://pejopazuzaguwoz.weebly.com/uploads/1/3/2/8/132815183/2599891.pdf
- https://tevirilozarenov.weebly.com/uploads/1/3/2/6/132695732/rezuno-labum-jobab.pdf
- https://finiluxexolije.weebly.com/uploads/1/3/1/8/131856594/9b296d6d3e3.pdf
- https://cdn.shopify.com/s/files/1/0437/7778/6018/files/lg_cell_phone_manuals_free.pdf
- https://cdn.shopify.com/s/files/1/0437/3826/7809/files/subaru_power_washer.pdf
- https://cdn.shopify.com/s/files/1/0431/8344/0036/files/arcs_central_angles_and_inscribed_angles_answers.pdf
- https://cdn.shopify.com/s/files/1/0433/5537/3720/files/2020_kitchen_design_download_cracked.pdf
- https://cdn.shopify.com/s/files/1/0268/8335/8914/files/33033901453.pdf
- https://kelobutino.weebly.com/uploads/1/3/0/9/130969458/ab8c589.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/bbb086.pdf
- https://cdn.shopify.com/s/files/1/0495/9174/6712/files/gladwell_outliers.pdf
- https://cdn.shopify.com/s/files/1/0500/2159/7333/files/opera_mini_beta_appsapk.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- wefolukozik.weebly.com
- ganulexotugoris.weebly.com
- xipunozelizu.weebly.com
- rabugotekinevod.weebly.com
- pejopazuzaguwoz.weebly.com
- tevirilozarenov.weebly.com
- finiluxexolije.weebly.com
- cdn.shopify.com
- kelobutino.weebly.com
- wepugimi.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report