MALICIOUS — 6168241.pdf
MALICIOUS — 6168241.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 1 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
dbe344dc848bf1e270693d25c5a01985a76d7a2cc423eb8196eb21700f6a5519 - SHA-1:
39a944a2e74b784e12100a96dd65173c5cfaff26 - MD5:
a0d3e37f32db3d0423f20e1da80a187b - ssdeep:
768:ZgGzpDspVIJ20mqOl4klHKIGl/c+ganSXWgYdVy8Hflxt:aGF4pAQGgY/yOflxt - TLSH:
T1E5304AF350A7EC8C7A8A5F039EAB215DA54AD78DA127DB90048C772DD47C9ED2F00921 - Submitted as: 6168241.pdf
- File type: pdf · Size: 38490 bytes
- Verdict: malicious (71/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/vigirupiruwovilav.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=wheel%20horse%20310-8%20parts%20list, https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/vigirupiruwovilav.pdf, https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/xopevu_vilugarokobijos_fimorekon.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=wheel%20horse%20310-8%20parts%20list
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/vigirupiruwovilav.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/xopevu_vilugarokobijos_fimorekon.pdf
- https://narogigadi.weebly.com/uploads/1/3/0/8/130874066/c2099e721b.pdf
- https://fekudumubaf.weebly.com/uploads/1/3/2/6/132681201/5761154.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/f9007.pdf
- https://cdn.shopify.com/s/files/1/0484/9834/4098/files/12651824512.pdf
- https://cdn.shopify.com/s/files/1/0481/4349/9413/files/79931104525.pdf
- https://cdn.shopify.com/s/files/1/0266/7646/1759/files/81224123079.pdf
- https://uploads.strikinglycdn.com/files/b9feb7bc-4178-4a96-a48b-55cfb6be53b7/21495545625.pdf
- https://uploads.strikinglycdn.com/files/0639a94c-3138-4255-bcbd-970b6ae91ba6/46967367775.pdf
- https://uploads.strikinglycdn.com/files/0817aa35-7588-42a8-98b7-92798eaa64a4/68730548428.pdf
- https://uploads.strikinglycdn.com/files/1ea55a6e-c30f-4ad6-9bb9-f13615935b90/83904981015.pdf
- https://cdn-cms.f-static.net/uploads/4365634/normal_5f87001b1a97b.pdf
- https://cdn-cms.f-static.net/uploads/4366676/normal_5f871c6d65867.pdf
- https://cdn-cms.f-static.net/uploads/4366017/normal_5f87014a569ac.pdf
- https://cdn-cms.f-static.net/uploads/4366048/normal_5f86f55969e60.pdf
- https://cdn-cms.f-static.net/uploads/4366055/normal_5f86f4b58bf8e.pdf
- https://site-1042658.mozfiles.com/files/1042658/64860491893.pdf
- https://site-1048530.mozfiles.com/files/1048530/fezumufesezoxalumoxat.pdf
- https://site-1036820.mozfiles.com/files/1036820/semisuxelonid.pdf
- https://site-1039560.mozfiles.com/files/1039560/49972798895.pdf
- https://site-1039129.mozfiles.com/files/1039129/71206170599.pdf
- https://uploads.strikinglycdn.com/files/e60ede4c-c0c0-49ad-aa4d-566a331b0726/vebedetififenokitediligu.pdf
- https://uploads.strikinglycdn.com/files/a0115663-fb28-41fc-bf47-9660b9bab260/23400052319.pdf
Embedded domains
- gettraff.ru
- dutitujazekap.weebly.com
- jawasolasazilem.weebly.com
- narogigadi.weebly.com
- fekudumubaf.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1042658.mozfiles.com
- site-1048530.mozfiles.com
- site-1036820.mozfiles.com
- site-1039560.mozfiles.com
- site-1039129.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report