MALICIOUS — 5819146159.pdf
MALICIOUS — 5819146159.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bceb2636efed91697af582e2713dd5eb4ca6eb49c9feb0378ac02b29476dcfff - SHA-1:
693fbf74c9856223c9127e1bd453f77402229fa6 - MD5:
94998934275cf0661ceca16f41eeb35c - ssdeep:
768:AgGzpDspSE4xFjWJhPHuTbDNBQeACLENnBuQM1c6el2xXT0VAotvOhK+s1:NGFApk77QM1NxXTQA0WhPs1 - TLSH:
T103316DF31097EE8C7A8B9F83ACB312A66489C7887232D7504498762DC47C5BDBF10961 - Submitted as: 5819146159.pdf
- File type: pdf · Size: 42968 bytes
- Verdict: malicious (71/100)
Detections (2 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/pugimus.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=dikkat+toplama+becerisini+geli%25C5%259Ftirici+etkinlikler+pdf, https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/pugimus.pdf, https://mogezisatizate.weebly.com/uploads/1/3/0/7/130775403/gawatetusut.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=dikkat+toplama+becerisini+geli%25C5%259Ftirici+etkinlikler+pdf
- https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/pugimus.pdf
- https://mogezisatizate.weebly.com/uploads/1/3/0/7/130775403/gawatetusut.pdf
- https://buxivadoga.weebly.com/uploads/1/3/0/7/130740323/dopup.pdf
- https://uploads.strikinglycdn.com/files/26d53df4-121b-45ce-92ea-13d9d874658b/28511802579.pdf
- https://uploads.strikinglycdn.com/files/ae27ba5a-6e8b-455b-a9f4-bcbe168e00ee/8982193979.pdf
- https://uploads.strikinglycdn.com/files/ccfca627-1614-4f74-8bbe-a2d7ecbafffe/depesefi.pdf
- https://uploads.strikinglycdn.com/files/d54836bb-323b-4687-8071-f433e4ff9ee0/25908219875.pdf
- https://uploads.strikinglycdn.com/files/a421afef-75b3-4646-968f-db18ad3e7713/34580376900.pdf
- https://uploads.strikinglycdn.com/files/b26ec52d-4182-48a7-b578-a26a307275b9/59639812323.pdf
- https://uploads.strikinglycdn.com/files/7af0aaf6-b710-4f34-bdea-bd99661349e3/78679654229.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/bamudepekepa_setumazowido.pdf
- https://vezorobabuwej.weebly.com/uploads/1/3/0/9/130969079/616f196.pdf
- https://pavowojavujide.weebly.com/uploads/1/3/1/3/131398322/tivuke-sigovitukom.pdf
- https://wovasemuzusalej.weebly.com/uploads/1/3/1/6/131636629/8039758.pdf
- https://koxoganonigowup.weebly.com/uploads/1/3/1/4/131408343/d6b8665e619d94.pdf
- https://cdn.shopify.com/s/files/1/0499/8473/3334/files/1_4oz_in_ml.pdf
- https://cdn.shopify.com/s/files/1/0437/3915/2536/files/sepajawuzupedikuvelomoj.pdf
- https://cdn.shopify.com/s/files/1/0434/1396/2908/files/predator_motorcycle_helmets_uk.pdf
- https://cdn.shopify.com/s/files/1/0434/3191/9765/files/inquiry_skills_activity_book_answers.pdf
- https://cdn.shopify.com/s/files/1/0476/8402/6527/files/juteduta.pdf
- https://cdn.shopify.com/s/files/1/0434/9342/5316/files/zivovatunazunopopigavuxo.pdf
- https://cdn.shopify.com/s/files/1/0436/6991/3753/files/92882670303.pdf
- https://cdn.shopify.com/s/files/1/0482/2653/3528/files/29450653165.pdf
- https://cdn.shopify.com/s/files/1/0437/2342/3912/files/97150299592.pdf
Embedded domains
- gettraff.ru
- vilukenuxe.weebly.com
- mogezisatizate.weebly.com
- buxivadoga.weebly.com
- uploads.strikinglycdn.com
- vuxozajuje.weebly.com
- vezorobabuwej.weebly.com
- pavowojavujide.weebly.com
- wovasemuzusalej.weebly.com
- koxoganonigowup.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report