MALICIOUS — 2171797.pdf
MALICIOUS — 2171797.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d6505cb8029a5ce4fa1385a7048a7859c962436b0c8871bbd7a341e027593f03 - SHA-1:
61d656cbba55c0ae60fcaa5d36519246807b6e3e - MD5:
37757dafd56cd9aae21cb78dc71e5e55 - ssdeep:
1536:qGFYpU3EvQKWvdvUgFLsVmw+NWy9Ya0W:TFYpU0WvdvU0LomHf9YA - TLSH:
T167359EF300D7DD4C798FAF17ADE710A9A449D78CA0369B9054C8B76CC0AC6EC6E11A51 - Submitted as: 2171797.pdf
- File type: pdf · Size: 57998 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://fekudumubaf.weebly.com/uploads/1/3/2/6/132681201/3321595.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=hp%20spectre%20x360%20battery%20life, https://fekudumubaf.weebly.com/uploads/1/3/2/6/132681201/3321595.pdf, https://genamimiwovem.weebly.com/uploads/1/3/1/6/131636881/balujewi_jivud_wulasewaxogemed.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=hp%20spectre%20x360%20battery%20life
- https://fekudumubaf.weebly.com/uploads/1/3/2/6/132681201/3321595.pdf
- https://genamimiwovem.weebly.com/uploads/1/3/1/6/131636881/balujewi_jivud_wulasewaxogemed.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/bamudepekepa_setumazowido.pdf
- https://cdn-cms.f-static.net/uploads/4369654/normal_5f885dc7d8479.pdf
- https://cdn-cms.f-static.net/uploads/4369783/normal_5f88125864305.pdf
- https://cdn-cms.f-static.net/uploads/4366317/normal_5f89c06730eb8.pdf
- https://cdn-cms.f-static.net/uploads/4370547/normal_5f8b7fd45e355.pdf
- https://cdn-cms.f-static.net/uploads/4368747/normal_5f8b737c6c808.pdf
- https://uploads.strikinglycdn.com/files/7e8bdfad-9f8e-416b-a704-1c65a935a56a/tesagerumevekapakax.pdf
- https://uploads.strikinglycdn.com/files/31051f96-2bd8-483c-a15d-33202b7c9a89/16562526845.pdf
- https://uploads.strikinglycdn.com/files/181fcc0b-9bb5-46aa-a7cb-3ceb8ef23cb6/19914833877.pdf
- https://sejevijuwev.weebly.com/uploads/1/3/2/7/132712154/2918706.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/fubisi.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/bupemigimamuvap.pdf
- https://folarudivol.weebly.com/uploads/1/3/1/8/131871739/nupivevepuneze.pdf
- https://uploads.strikinglycdn.com/files/a5105c73-908e-4b42-90d2-24b06db97910/9631332220.pdf
- https://uploads.strikinglycdn.com/files/85712a97-611b-4af2-ba8b-615a1330dbfd/65571043568.pdf
- https://uploads.strikinglycdn.com/files/94529dbd-a8c3-43a0-97b1-20928cdabb68/58158603528.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f87557f8c4f8.pdf
- https://cdn-cms.f-static.net/uploads/4368768/normal_5f8a99e57f5bf.pdf
- https://cdn-cms.f-static.net/uploads/4375528/normal_5f8bfb5c104f4.pdf
- https://cdn-cms.f-static.net/uploads/4366017/normal_5f89c1ce53dcc.pdf
- https://cdn-cms.f-static.net/uploads/4378406/normal_5f8a0fda4776d.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- fekudumubaf.weebly.com
- genamimiwovem.weebly.com
- vuxozajuje.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- sejevijuwev.weebly.com
- dutitujazekap.weebly.com
- fijojonibiw.weebly.com
- folarudivol.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report