MALICIOUS — 3e95ba35f3e2ae.pdf
MALICIOUS — 3e95ba35f3e2ae.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c90e966fd00fb023d2a2c953633c1490e237ad57c965698f01dfd135b46a3d57 - SHA-1:
f92ae483cf3a966dd2a196344a49d2ca734337d8 - MD5:
e718dd2e6c9257325af4a65454b50de5 - ssdeep:
768:dgGzpDy/xxiADnZI1ZZ7wZ5MZuJDGz7jtTvL/cu9mnwD87OtbR4xO5:eGFoXAPJTn9mEHtbR4xO5 - TLSH:
T1F0317EF351A7ED8C7A8AAF236D6B259D644AC78C7033C6600488772DD47C6BD7E01862 - Submitted as: 3e95ba35f3e2ae.pdf
- File type: pdf · Size: 39562 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://xigokerurubupa.weebly.com/uploads/1/3/4/3/134312623/mevefizafubumuvive.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=dividing%20fractions%20word%20problems%20pdf, https://xigokerurubupa.weebly.com/uploads/1/3/4/3/134312623/mevefizafubumuvive.pdf, https://pipalilivo.weebly.com/uploads/1/3/4/3/134310902/nidagodi_gupavizon.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=dividing%20fractions%20word%20problems%20pdf
- https://s3.amazonaws.com/jenagubadopi/read_the_birchbark_house.pdf
- https://xigokerurubupa.weebly.com/uploads/1/3/4/3/134312623/mevefizafubumuvive.pdf
- https://pipalilivo.weebly.com/uploads/1/3/4/3/134310902/nidagodi_gupavizon.pdf
- https://uploads.strikinglycdn.com/files/79d17cf8-0b7a-4b3f-862a-9ddbc17bba81/kasulagemaninirimodow.pdf
- https://uploads.strikinglycdn.com/files/cedd1498-17d5-4f2d-8b16-13df55ba991d/2277424519.pdf
- https://cdn-cms.f-static.net/uploads/4385231/normal_5f8d327e60c10.pdf
- https://tusutaxuwipafu.weebly.com/uploads/1/3/4/4/134403355/3989965.pdf
- https://uploads.strikinglycdn.com/files/dd72d830-5560-4e89-8587-70845bd88d5a/rimosezo.pdf
- https://cdn-cms.f-static.net/uploads/4375076/normal_5f90b014330ea.pdf
- https://cdn-cms.f-static.net/uploads/4413966/normal_5f964b26035de.pdf
- https://xomevore.weebly.com/uploads/1/3/4/3/134346529/nekibawasez.pdf
- https://rejileju.weebly.com/uploads/1/3/4/3/134335231/xesosam.pdf
- https://cdn-cms.f-static.net/uploads/4366321/normal_5f94342413d0f.pdf
- https://cdn-cms.f-static.net/uploads/4380858/normal_5f8cccad2f36e.pdf
- https://lebuwaner.weebly.com/uploads/1/3/4/4/134478239/bujegiz.pdf
- https://cdn-cms.f-static.net/uploads/4369187/normal_5f8b94cd7576c.pdf
- https://velulaganivuvoj.weebly.com/uploads/1/3/4/4/134438708/nafuxamijufifiwi.pdf
- https://uploads.strikinglycdn.com/files/090574b6-97ce-4f5b-94da-fef6c976876d/dinamicas_de_autoestima.pdf
- https://cdn-cms.f-static.net/uploads/4382407/normal_5f99de48c4981.pdf
- https://uploads.strikinglycdn.com/files/ae3db573-2066-4543-9a5b-db0ef073eb20/74560160550.pdf
- https://cdn-cms.f-static.net/uploads/4393179/normal_5f95056b3e97a.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- s3.amazonaws.com
- xigokerurubupa.weebly.com
- pipalilivo.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- tusutaxuwipafu.weebly.com
- xomevore.weebly.com
- rejileju.weebly.com
- lebuwaner.weebly.com
- velulaganivuvoj.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report