MALICIOUS — 21b2421104a0.pdf
MALICIOUS — 21b2421104a0.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e161fb5b78dcbf3615c9479d5021e60f90350d3a86b18ad14dfe1c6eae3d94a9 - SHA-1:
12bc7ab2814f988bca59fc4a2931857dccf71747 - MD5:
5ebcad6c58317215362e824ea7142827 - ssdeep:
768:lgGzpDSpMCGGnzkExIpnhk1MInxOE9EI5OBQYXrGwEL5OOq20b5QxrQA2OeQhhO:2GF+pMCrtIpnhe2PQgowOR0bGxEA2Oeh - TLSH:
T117327CF3506BED4C79879F837DAB219EA049C78C6132A7644498766CC8BC6BD3F01A11 - Submitted as: 21b2421104a0.pdf
- File type: pdf · Size: 45646 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://gemaxudemaxepeb.weebly.com/uploads/1/3/1/0/131070646/niwexekeropeveteken.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=principe%20de%20fonctionnement%20d%20un%20onduleur, https://vuzevarezevarot.weebly.com/uploads/1/3/0/7/130740461/2244882.pdf, https://gemaxudemaxepeb.weebly.com/uploads/1/3/1/0/131070646/niwexekeropeveteken.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=principe%20de%20fonctionnement%20d%20un%20onduleur
- https://vuzevarezevarot.weebly.com/uploads/1/3/0/7/130740461/2244882.pdf
- https://gemaxudemaxepeb.weebly.com/uploads/1/3/1/0/131070646/niwexekeropeveteken.pdf
- https://vimiwegom.weebly.com/uploads/1/3/0/7/130775837/gipevododur.pdf
- https://xojisige.weebly.com/uploads/1/3/1/6/131637148/5910241.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/7061675.pdf
- https://cdn-cms.f-static.net/uploads/4366365/normal_5f87b0047d464.pdf
- https://site-1043976.mozfiles.com/files/1043976/kujexoputugenodapodarol.pdf
- https://site-1041695.mozfiles.com/files/1041695/wuvetal.pdf
- https://site-1043808.mozfiles.com/files/1043808/lugorilogenigulogotip.pdf
- https://site-1039617.mozfiles.com/files/1039617/pepitaxefemeforidodu.pdf
- https://cdn-cms.f-static.net/uploads/4366662/normal_5f87a8894bb9b.pdf
- https://cdn-cms.f-static.net/uploads/4366311/normal_5f87544525253.pdf
- https://cdn-cms.f-static.net/uploads/4366340/normal_5f87246ec40cc.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f871879df333.pdf
- https://liwevapazu.weebly.com/uploads/1/3/1/0/131071299/jugibolimeketavo.pdf
- https://vopevejefed.weebly.com/uploads/1/3/1/6/131606133/6941374.pdf
- https://rakamukomegu.weebly.com/uploads/1/3/2/6/132681656/9889394.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/jibepare-vudaramuzi-refirezagulele.pdf
- https://femevidawivuk.weebly.com/uploads/1/3/1/0/131071063/53ef91cec69bef.pdf
- https://uploads.strikinglycdn.com/files/0f09d7cd-4950-404b-96d3-b8864d517946/bikolutikepebaninikolufi.pdf
- https://uploads.strikinglycdn.com/files/075e5844-ec99-4888-aeb1-b249a555f96f/94098861097.pdf
- https://uploads.strikinglycdn.com/files/43083e61-1ec4-4251-bd9d-dd088191a2c7/difijedewajumufe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- vuzevarezevarot.weebly.com
- gemaxudemaxepeb.weebly.com
- vimiwegom.weebly.com
- xojisige.weebly.com
- gimejexoxixaza.weebly.com
- cdn-cms.f-static.net
- site-1043976.mozfiles.com
- site-1041695.mozfiles.com
- site-1043808.mozfiles.com
- site-1039617.mozfiles.com
- liwevapazu.weebly.com
- vopevejefed.weebly.com
- rakamukomegu.weebly.com
- mogilifus.weebly.com
- femevidawivuk.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report