MALICIOUS — dcc9b2ec.pdf
MALICIOUS — dcc9b2ec.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d07dd1ea38f9dcf619616fb697f3a32036194b3ad627e23cffa8de6c755d4f21 - SHA-1:
3fdb97664015a4bc7a12243723c8d68f6d0dab36 - MD5:
3d7173ec352f851508b909c822b676b6 - ssdeep:
768:6gGzpDSpfiI9DiD31O1Oz3uCQEU5k5T83j+jWynxES/YSFDFD:nGFGpfi/1gOz3uDElO3j+jWynRYaDFD - TLSH:
T184339EF314A7DD8C7B8AAF03ACBB2429508AD3886132D7A05488776D857C6BD7F11D60 - Submitted as: dcc9b2ec.pdf
- File type: pdf · Size: 47802 bytes
- Verdict: malicious (75/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/62be3edfc1.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=olympus%20cx43%20manual%20pdf, https://sepenunaxob.weebly.com/uploads/1/3/0/7/130776074/30d1d49601fae34.pdf, https://bubiwodepu.weebly.com/uploads/1/3/2/8/132815961/8f5e938c2cf87ff.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=olympus%20cx43%20manual%20pdf
- https://sepenunaxob.weebly.com/uploads/1/3/0/7/130776074/30d1d49601fae34.pdf
- https://bubiwodepu.weebly.com/uploads/1/3/2/8/132815961/8f5e938c2cf87ff.pdf
- https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/62be3edfc1.pdf
- https://uploads.strikinglycdn.com/files/f449110c-85d1-4c6a-aa58-8f0cc53a32c5/xudedajatujo.pdf
- https://zavomafig.weebly.com/uploads/1/3/4/3/134356936/magijujiku.pdf
- https://xubuvene.weebly.com/uploads/1/3/1/3/131380433/fitilila-virajem.pdf
- https://popekuzukije.weebly.com/uploads/1/3/4/4/134471955/c6b7ce2904ff.pdf
- https://wopeduvolevim.weebly.com/uploads/1/3/0/7/130776212/moluluxunemolux_witajipupujaru.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/7805117.pdf
- https://uploads.strikinglycdn.com/files/f2c11d43-3c97-4cf9-b26a-8f9529128e41/starbucks_coffee_passport_notes.pdf
- https://uploads.strikinglycdn.com/files/591aba45-65c8-42a9-bfab-09377da0dc67/10046269579.pdf
- https://uploads.strikinglycdn.com/files/325b19d9-b38d-4b76-8792-4bdb1c625c69/95963155153.pdf
- https://uploads.strikinglycdn.com/files/e36b6bbb-0905-4a01-9425-65c9404ab2de/xeduziwopopolo.pdf
- https://uploads.strikinglycdn.com/files/e736d25d-bfa8-4176-a764-ffa499ae27bc/jubaranateruzusaro.pdf
- https://mumixopid.weebly.com/uploads/1/3/1/8/131872042/fejebo.pdf
- https://kenilajapa.weebly.com/uploads/1/3/1/0/131069910/d26353a63e9b0de.pdf
- https://uploads.strikinglycdn.com/files/84ee1fe8-ae14-4914-879a-99f0256a3c0b/momelibuvafokatajosasaz.pdf
- https://uploads.strikinglycdn.com/files/ab9b1f79-7916-43f6-b3ab-8a5686e16daf/etumax_royal_honey_como_se_toma.pdf
- https://uploads.strikinglycdn.com/files/007bc2e4-f5c0-4d1d-a904-88dbc5332592/golf_clash_wind_chart.pdf
- https://uploads.strikinglycdn.com/files/a50d8b79-5a58-434e-9d86-19077a3094f6/92209427628.pdf
- https://uploads.strikinglycdn.com/files/bd5c565b-d8c1-4c52-a77d-a0b10c8fd405/zesatural.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- sepenunaxob.weebly.com
- bubiwodepu.weebly.com
- vilukenuxe.weebly.com
- uploads.strikinglycdn.com
- zavomafig.weebly.com
- xubuvene.weebly.com
- popekuzukije.weebly.com
- wopeduvolevim.weebly.com
- mogilifus.weebly.com
- mumixopid.weebly.com
- kenilajapa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- T:\`k
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report