MALICIOUS — 1973313.pdf
MALICIOUS — 1973313.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
cee2155275ce54a7ebda05824468d57d8745a24a4f8acdf312568e59d164b92e - SHA-1:
e81a389163d37016095d8d68867edb24355b941d - MD5:
16bd7ef92ad2ad2d6a548036bc975435 - ssdeep:
768:mgGzpDwXxS8y7QFd5ehv2S5gP54ExWYZkE5n5kJ0ii6hpRk:zGF0hS8t5ehv2S5gXWYZz6qiiopRk - TLSH:
T17532ADF350D7DC8C7A8A9B135CEB1569908AD38D7137D6A048C83B2DC4BC2AD6E50C61 - Submitted as: 1973313.pdf
- File type: pdf · Size: 46513 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/3355978.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=gatti%20ice%20cream%20price%20list%202019%20pdf, https://pepuzategazeg.weebly.com/uploads/1/3/1/4/131453576/7702686.pdf, https://jukafubu.weebly.com/uploads/1/3/0/8/130874261/c7f721eff6e7.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=gatti%20ice%20cream%20price%20list%202019%20pdf
- https://pepuzategazeg.weebly.com/uploads/1/3/1/4/131453576/7702686.pdf
- https://jukafubu.weebly.com/uploads/1/3/0/8/130874261/c7f721eff6e7.pdf
- https://juxupadozimufa.weebly.com/uploads/1/3/4/3/134388451/6f2169971f.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/jazoxulipube.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/3355978.pdf
- https://s3.amazonaws.com/felasorarabipis/74101631488.pdf
- https://s3.amazonaws.com/henghuili-files2/97876312959.pdf
- https://s3.amazonaws.com/paxivogedewilu/basic_korean_language_tutorial.pdf
- https://s3.amazonaws.com/henghuili-files/castelnuovo_tedesco_fantasia_op_145.pdf
- https://uploads.strikinglycdn.com/files/9a2a1787-205c-4481-9b68-9bce2fbc7517/21543178027.pdf
- https://uploads.strikinglycdn.com/files/71be519f-c922-4545-b4a1-166a2f1429f6/kagan_cooperative_learning_strategie.pdf
- https://uploads.strikinglycdn.com/files/a8a5d3a9-9eae-4435-8bc3-3106a1133ff6/8624771821.pdf
- https://uploads.strikinglycdn.com/files/8aa3082f-7511-421f-afaa-c26049efcdec/88038130971.pdf
- https://uploads.strikinglycdn.com/files/80aca7ed-607b-4a5a-8bf7-44fdc5ffa468/7366511329.pdf
- https://cdn-cms.f-static.net/uploads/4375531/normal_5f92c32548c32.pdf
- https://cdn-cms.f-static.net/uploads/4387061/normal_5f917716714b3.pdf
- https://fadusoga.weebly.com/uploads/1/3/0/7/130739873/6202603.pdf
- https://podesasi.weebly.com/uploads/1/3/1/4/131437149/6068155.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- pepuzategazeg.weebly.com
- jukafubu.weebly.com
- juxupadozimufa.weebly.com
- xojerajap.weebly.com
- gimejexoxixaza.weebly.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- fadusoga.weebly.com
- podesasi.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report