MALICIOUS — fometaja.pdf
MALICIOUS — fometaja.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 1 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c1130f5eca59116836b219298d093551bb0f5bbfe4a6f6ce78458ec873411652 - SHA-1:
cac06502831adbecabba7cdda97b6aa9ee6f1deb - MD5:
a96e43ab43aa7b3c40fed075862d0db7 - ssdeep:
768:2KgGzpDDpmlfw1hPnzBOC0CAaSo6ub+lCOtC7n+KbtY625Omkj4dGQu2r:YGFfpEilj+lCOC7nYHjnu2r - TLSH:
T125316CF340ABEE4C7AC7AB036EFA255D504ED6486032A7604888772DD4BC77E3E10A51 - Submitted as: fometaja.pdf
- File type: pdf · Size: 39471 bytes
- Verdict: malicious (71/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://gukaguse.weebly.com/uploads/1/3/1/3/131398473/fbd31b.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=introducing%20the%20positions%20for%20violin, https://cdn.shopify.com/s/files/1/0481/5224/8482/files/74519827312.pdf, https://cdn.shopify.com/s/files/1/0437/7355/8935/files/que_es_cinetica.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=introducing%20the%20positions%20for%20violin
- https://cdn.shopify.com/s/files/1/0481/5224/8482/files/74519827312.pdf
- https://cdn.shopify.com/s/files/1/0437/7355/8935/files/que_es_cinetica.pdf
- https://cdn.shopify.com/s/files/1/0500/9086/8901/files/tennis_video_games_xbox_one.pdf
- https://cdn.shopify.com/s/files/1/0484/5017/5126/files/49652701292.pdf
- https://cdn.shopify.com/s/files/1/0462/7274/1525/files/vadofisize.pdf
- https://cdn-cms.f-static.net/uploads/4365583/normal_5f873236e87ba.pdf
- https://cdn-cms.f-static.net/uploads/4365570/normal_5f88c03a0ebfe.pdf
- https://xawuwotogot.weebly.com/uploads/1/3/2/6/132695388/vasekere.pdf
- https://gukaguse.weebly.com/uploads/1/3/1/3/131398473/fbd31b.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/likanutavorolebonat.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/8980310.pdf
- https://tudupumodowi.weebly.com/uploads/1/3/1/4/131406798/b726ec796bb5.pdf
- https://uploads.strikinglycdn.com/files/b7c60727-2a83-4b32-8750-5cff394cd781/94041807477.pdf
- https://uploads.strikinglycdn.com/files/a5265071-b1ab-40e2-b996-ac8844cd2b96/93098757866.pdf
- https://uploads.strikinglycdn.com/files/4ae964e0-639c-4539-a8d1-b9e625168bb2/wapinurag.pdf
- https://uploads.strikinglycdn.com/files/6375b3b6-2b46-449d-9cb0-bb118a4a18c7/89434386389.pdf
- https://uploads.strikinglycdn.com/files/3001a8b2-1a6f-4f76-827e-8d4145e867e6/zuzerovopexugebi.pdf
- https://uploads.strikinglycdn.com/files/cde6f824-4959-4e24-94df-f7a71378135c/rufamezef.pdf
- https://uploads.strikinglycdn.com/files/5fbf7c4c-6da0-4003-b8a4-73bd8bafa21b/69439123935.pdf
- https://uploads.strikinglycdn.com/files/52d69a83-3de8-45a8-a892-cb1864855847/belesikenoz.pdf
- https://uploads.strikinglycdn.com/files/1ab2cdac-7ceb-4e08-989c-4ada64d4b36e/nelopobovavokased.pdf
- https://uploads.strikinglycdn.com/files/73805e4a-7c3e-4dc8-9c60-d4221e5a6461/vevevutowamilapefiwaxo.pdf
- https://uploads.strikinglycdn.com/files/e91b954e-c962-4aab-b674-c88387ee845a/waboz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- xawuwotogot.weebly.com
- gukaguse.weebly.com
- jakedekokobara.weebly.com
- vuxozajuje.weebly.com
- tudupumodowi.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report