MALICIOUS — 5524636.pdf
MALICIOUS — 5524636.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e0cb79db3e0b4e9ebce2bac1d9c52977bcf5e1ca6bd43c017c2b25c0c9f48b9c - SHA-1:
2c0a52add8a0c2c7f5c99f3e202aba8dd7499d98 - MD5:
d41472aa0239fdbad937e607bb2323f9 - ssdeep:
768:GgGzpDjphywnq9Y3fiLklhkt4d3HeCqsnNmOei7/Qx7rRj5mVo4GWUs/R:TGFvptZfyUS3i7/Qx7rFEEWUs/R - TLSH:
T1B1327CF311A7EE4C7987DB03AAEB291DA14AD788A17397640488662CC5BC77D3F10960 - Submitted as: 5524636.pdf
- File type: pdf · Size: 45454 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/6363393.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=hot%20spring%20spa%20sovereign%20manual, https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/6363393.pdf, https://zimiduninu.weebly.com/uploads/1/3/1/6/131637103/3977069.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=hot%20spring%20spa%20sovereign%20manual
- https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/6363393.pdf
- https://zimiduninu.weebly.com/uploads/1/3/1/6/131637103/3977069.pdf
- https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/dususoxepebo-besusa-ruwasuvukedef-jomar.pdf
- https://viweposedijul.weebly.com/uploads/1/3/1/0/131070314/17563d38f77.pdf
- https://worobewunit.weebly.com/uploads/1/3/1/4/131406731/61a0a9e01b0179.pdf
- https://gemenudotipetal.weebly.com/uploads/1/3/2/6/132695720/2957024.pdf
- https://tejojobowadame.weebly.com/uploads/1/3/0/8/130874570/janozaxeres.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/76c30d49.pdf
- https://site-1036729.mozfiles.com/files/1036729/xisenox.pdf
- https://site-1043475.mozfiles.com/files/1043475/40759165105.pdf
- https://site-1038423.mozfiles.com/files/1038423/34045829716.pdf
- https://site-1039607.mozfiles.com/files/1039607/79597909145.pdf
- https://site-1040785.mozfiles.com/files/1040785/rojafefegeti.pdf
- https://uploads.strikinglycdn.com/files/9ef41b35-5487-4feb-869a-77aff819e345/90709644091.pdf
- https://uploads.strikinglycdn.com/files/940cded5-d8df-4ec1-9534-af1b8d626ac1/xakofupegoxifukitifewepaw.pdf
- https://uploads.strikinglycdn.com/files/5693515b-5ad0-4d3b-a59d-6048108885bd/wubapurilagarobufetakata.pdf
- https://uploads.strikinglycdn.com/files/8a1bf5bb-192c-44a6-9742-5f4ebda91665/nifonevotinu.pdf
- https://cdn-cms.f-static.net/uploads/4365552/normal_5f8702c9ca0d8.pdf
- https://cdn-cms.f-static.net/uploads/4365653/normal_5f870dfeecd19.pdf
- https://cdn.shopify.com/s/files/1/0497/8560/2215/files/tobutexolevis.pdf
- https://cdn.shopify.com/s/files/1/0494/3049/5399/files/8309957230.pdf
- https://cdn.shopify.com/s/files/1/0500/4905/6918/files/45944459226.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- nudojafobedem.weebly.com
- zimiduninu.weebly.com
- besiwalufeg.weebly.com
- viweposedijul.weebly.com
- worobewunit.weebly.com
- gemenudotipetal.weebly.com
- tejojobowadame.weebly.com
- dutitujazekap.weebly.com
- site-1036729.mozfiles.com
- site-1043475.mozfiles.com
- site-1038423.mozfiles.com
- site-1039607.mozfiles.com
- site-1040785.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report