MALICIOUS — 1904209.pdf
MALICIOUS — 1904209.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b7cc9bc349abe9a3d968e873a26cafaf58d93bd5b3fae8cb9e2e1d9f5e74ed9b - SHA-1:
0fe8cbec01fee1848eff2dd8ec712af338d2ed91 - MD5:
7a9f62298876498e5862a9faa82e9f1e - ssdeep:
768:pgGzpDbplUSta03I6s7TG7EArHpiy77hc6z9OQYpt:KGFXpXs0iPG7TpNROQYpt - TLSH:
T1A6306DF350A7ED4C3ACB9B03AEAE254D9089E7885132D7604498772DC4BC3BE6F50961 - Submitted as: 1904209.pdf
- File type: pdf · Size: 39153 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://debasomi.weebly.com/uploads/1/3/0/7/130739769/18b3dc9062.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=pottery%20barn%20convertible%20crib, https://uploads.strikinglycdn.com/files/8c52d7a6-2ef2-4796-b7b9-ead8ffaad813/xoviworutu.pdf, https://uploads.strikinglycdn.com/files/50c62bbf-d6e8-4d4d-b914-13122560bb44/fipibotuvoro.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=pottery%20barn%20convertible%20crib
- https://uploads.strikinglycdn.com/files/8c52d7a6-2ef2-4796-b7b9-ead8ffaad813/xoviworutu.pdf
- https://uploads.strikinglycdn.com/files/50c62bbf-d6e8-4d4d-b914-13122560bb44/fipibotuvoro.pdf
- https://uploads.strikinglycdn.com/files/7a523dae-cf32-4b61-9974-3a3fa9296a07/98428824219.pdf
- https://fisotewefupug.weebly.com/uploads/1/3/1/0/131071176/5736233.pdf
- https://debasomi.weebly.com/uploads/1/3/0/7/130739769/18b3dc9062.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/9276785.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/wovexofek.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/vifotatilaw.pdf
- https://xumogimunosu.weebly.com/uploads/1/3/1/6/131607683/a73cbec3e716.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/runemevurexuziwone.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/5058540.pdf
- https://voledobaseju.weebly.com/uploads/1/3/0/9/130969813/5afd26acf957.pdf
- https://uploads.strikinglycdn.com/files/bfb6c0e1-534d-4892-b1d2-5cfa4f188a76/2534987754.pdf
- https://uploads.strikinglycdn.com/files/28f5255e-79b3-48a8-b257-9810af439319/ruvuse.pdf
- https://site-1037018.mozfiles.com/files/1037018/21927532216.pdf
- https://site-1044060.mozfiles.com/files/1044060/87886044850.pdf
- https://site-1039303.mozfiles.com/files/1039303/sadelanigimawovazatok.pdf
- https://site-1038612.mozfiles.com/files/1038612/xufagufobosogiw.pdf
- https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/03b622.pdf
- https://walijogopabo.weebly.com/uploads/1/3/0/7/130776167/da942785a349.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/fibawubaxavuvabu.pdf
- https://ridolagu.weebly.com/uploads/1/3/0/7/130775195/4557862.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- fisotewefupug.weebly.com
- debasomi.weebly.com
- dutitujazekap.weebly.com
- jawasolasazilem.weebly.com
- fijojonibiw.weebly.com
- xumogimunosu.weebly.com
- genigudepa.weebly.com
- voledobaseju.weebly.com
- site-1037018.mozfiles.com
- site-1044060.mozfiles.com
- site-1039303.mozfiles.com
- site-1038612.mozfiles.com
- pigogokeda.weebly.com
- walijogopabo.weebly.com
- keniwuki.weebly.com
- ridolagu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report