MALICIOUS — 930e76ac1f871.pdf
MALICIOUS — 930e76ac1f871.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
de78fa957317ef7f60141f0d7ea9ceba6f37b069c8ebda415df6fe5400fb226d - SHA-1:
ff7cafadd1eabc47a6bc0b9c4fb62d93e5063d5f - MD5:
d6c57ac54a0981098a4f6b7f13971e5b - ssdeep:
1536:iGFNprAQrw7koCpm/pYKkcnm6LDn6EKZiwMAdR5RfRWN4wS5EgP:bFNpka2IKmKkYPfn6VgQRf2zS57 - TLSH:
T12A37BFF700A3ED4C7A879B536DF6215C658AD789A172AB9084882B2EC07C77E7F01941 - Submitted as: 930e76ac1f871.pdf
- File type: pdf · Size: 75606 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://roninuvanajeg.weebly.com/uploads/1/3/1/3/131379749/5068852.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=ye%20are%20gods%20annalee%20skarin, https://site-1043853.mozfiles.com/files/1043853/norakujasuzufosaze.pdf, https://site-1043437.mozfiles.com/files/1043437/kazefet.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=ye%20are%20gods%20annalee%20skarin
- https://site-1043853.mozfiles.com/files/1043853/norakujasuzufosaze.pdf
- https://site-1043437.mozfiles.com/files/1043437/kazefet.pdf
- https://site-1039174.mozfiles.com/files/1039174/nejaxovexapibetaga.pdf
- https://site-1041688.mozfiles.com/files/1041688/jubanokodatezijevopu.pdf
- https://site-1042821.mozfiles.com/files/1042821/bapuwonozovud.pdf
- https://gewosawoma.weebly.com/uploads/1/3/0/7/130739201/pezamamijajuxeruwima.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/93049f265a0000.pdf
- https://roninuvanajeg.weebly.com/uploads/1/3/1/3/131379749/5068852.pdf
- https://rabugotekinevod.weebly.com/uploads/1/3/1/8/131871666/vakukil-sinidebazedu-burewevito-milumaxemomazu.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/08a5ecf796.pdf
- https://site-1042556.mozfiles.com/files/1042556/81876207271.pdf
- https://site-1040574.mozfiles.com/files/1040574/rekapunokiwewemuzifonafen.pdf
- https://site-1044020.mozfiles.com/files/1044020/kezarilazitidadarade.pdf
- https://site-1042888.mozfiles.com/files/1042888/62955299418.pdf
- https://site-1042787.mozfiles.com/files/1042787/35579518959.pdf
- https://uploads.strikinglycdn.com/files/71dba2b2-2cb6-4518-88b2-528c3ecc9945/fudijawukekunodule.pdf
- https://uploads.strikinglycdn.com/files/eb0faca3-8e05-4971-843f-e8857a110b55/85445947395.pdf
- https://uploads.strikinglycdn.com/files/33025069-78a0-4637-9366-456c721a613a/32447740230.pdf
- https://uploads.strikinglycdn.com/files/86065947-e96c-4c4a-9bcf-587589ae1f67/5205664711.pdf
- https://uploads.strikinglycdn.com/files/f2db704b-41f5-44dd-9fcd-c5013a0680fd/kijutemuwiwis.pdf
- https://site-1039509.mozfiles.com/files/1039509/91722449488.pdf
- https://site-1048162.mozfiles.com/files/1048162/xerisevosoliguwabe.pdf
- https://site-1048515.mozfiles.com/files/1048515/58112412621.pdf
- https://site-1038627.mozfiles.com/files/1038627/vomepivisulefoke.pdf
Embedded domains
- gettraff.ru
- site-1043853.mozfiles.com
- site-1043437.mozfiles.com
- site-1039174.mozfiles.com
- site-1041688.mozfiles.com
- site-1042821.mozfiles.com
- gewosawoma.weebly.com
- zoxuzuxebexot.weebly.com
- roninuvanajeg.weebly.com
- rabugotekinevod.weebly.com
- jufaxexave.weebly.com
- site-1042556.mozfiles.com
- site-1040574.mozfiles.com
- site-1044020.mozfiles.com
- site-1042888.mozfiles.com
- site-1042787.mozfiles.com
- uploads.strikinglycdn.com
- site-1039509.mozfiles.com
- site-1048162.mozfiles.com
- site-1048515.mozfiles.com
- site-1038627.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report