MALICIOUS — ratumuram.pdf
MALICIOUS — ratumuram.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
cc36403a52bf53cba3eb577fc26a4a8785dc91157646dd3f6fd7fb2ac99bda4c - SHA-1:
1a86d28827ad92e912679dfe0f98c850dbc8a22d - MD5:
c846e5d9fac0e79734d2863198dfa02b - ssdeep:
768:IgGzpD/1DYwTSySWpy9sBJhlFQcBHsg4fuWCudllC1:FGF71sepy9sBBFQcVeu/OlC1 - TLSH:
T1212F7EF320A7DC8C6A866B03ADA61059704AC74C61369A7059EDB73CC8FC6BD6E10961 - Submitted as: ratumuram.pdf
- File type: pdf · Size: 32847 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/3808383.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=precalculus%20summer%20packet%20with%20answers, https://fepobiwebefu.weebly.com/uploads/1/3/4/5/134592484/pimijutudidog.pdf, https://fafugugopogewip.weebly.com/uploads/1/3/4/4/134464831/39808853dc9d.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=precalculus%20summer%20packet%20with%20answers
- https://fepobiwebefu.weebly.com/uploads/1/3/4/5/134592484/pimijutudidog.pdf
- https://fafugugopogewip.weebly.com/uploads/1/3/4/4/134464831/39808853dc9d.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/3808383.pdf
- https://cdn-cms.f-static.net/uploads/4380383/normal_5f8cbe1c71048.pdf
- https://sakukavazu.weebly.com/uploads/1/3/1/3/131379729/kupidulizatep_guxuvov_geropixapiki_lonajosujogom.pdf
- https://regukabomuvan.weebly.com/uploads/1/3/4/4/134471867/3781398.pdf
- https://cdn-cms.f-static.net/uploads/4390641/normal_5f992fbb9f74d.pdf
- https://cdn.shopify.com/s/files/1/0486/2633/5909/files/nevadegelakegoviba.pdf
- https://s3.amazonaws.com/wisuw/colorado_springs_christmas_light_extravaganza.pdf
- https://zifidobu.weebly.com/uploads/1/3/4/3/134371145/pubuwutokuniwof.pdf
- https://dizakevusarebiz.weebly.com/uploads/1/3/4/5/134581037/388317.pdf
- https://numobokofe.weebly.com/uploads/1/3/4/5/134501802/504e83beccc7447.pdf
- https://fivilogavizizov.weebly.com/uploads/1/3/4/4/134446089/395598.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- fepobiwebefu.weebly.com
- fafugugopogewip.weebly.com
- gimejexoxixaza.weebly.com
- cdn-cms.f-static.net
- sakukavazu.weebly.com
- regukabomuvan.weebly.com
- cdn.shopify.com
- s3.amazonaws.com
- zifidobu.weebly.com
- dizakevusarebiz.weebly.com
- numobokofe.weebly.com
- fivilogavizizov.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report