MALICIOUS — 69d081fa.pdf
MALICIOUS — 69d081fa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e2b962697a3ae7f2612e073ef165fbcaa399b535d79ed93f6be86b1c01eaaf81 - SHA-1:
3d360b090ad687eccaa9e1d3c597d74d3865c489 - MD5:
314a53c933f23eca855624c1a17daada - ssdeep:
768:hgGzpDhDVhra8t5MgvRtYVd5Y0zraxavpBDkSEnlP85KpkWg51ZaZPIterR:SGFF5dwzecxBDkPlP8kpkWUWiterR - TLSH:
T144338EF3109BDE5C7B8B9B17ADAB185DA45DD348A1329BA4058D773CC0BC6AD3E005A0 - Submitted as: 69d081fa.pdf
- File type: pdf · Size: 48551 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/05c0c091-4840-4862-8e1b-4fe2cf816328/66664482754.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=first%20amendment%20usa%20pdf, https://uploads.strikinglycdn.com/files/05c0c091-4840-4862-8e1b-4fe2cf816328/66664482754.pdf, https://kubuwexujilo.weebly.com/uploads/1/3/4/4/134473085/vajig-simubig-gevekawuzi-wemod.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=first%20amendment%20usa%20pdf
- https://uploads.strikinglycdn.com/files/05c0c091-4840-4862-8e1b-4fe2cf816328/66664482754.pdf
- https://kubuwexujilo.weebly.com/uploads/1/3/4/4/134473085/vajig-simubig-gevekawuzi-wemod.pdf
- https://cdn-cms.f-static.net/uploads/4407062/normal_5f95ddeb5c621.pdf
- https://cdn-cms.f-static.net/uploads/4367294/normal_5f8754434c446.pdf
- https://s3.amazonaws.com/pazifetanegapu/baeyer_villiger_rearrangement.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/nidisetati.pdf
- https://s3.amazonaws.com/paropabaru/koxumufawujurilebep.pdf
- https://temazojirilezin.weebly.com/uploads/1/3/2/3/132302863/a98c9cfca0e2.pdf
- https://cdn-cms.f-static.net/uploads/4381302/normal_5f8f3b148429f.pdf
- https://s3.amazonaws.com/kavitokolezub/multiplication_worksheets_year_4.pdf
- https://uploads.strikinglycdn.com/files/7c95aaae-b722-4dfa-924e-de21e390647c/buwawelogokadi.pdf
- https://cdn-cms.f-static.net/uploads/4380379/normal_5f8d9e45b5836.pdf
- https://uploads.strikinglycdn.com/files/8d8c2f3a-00e7-44e3-b550-2a4c31db0009/vewapuzopadi.pdf
- https://cdn-cms.f-static.net/uploads/4402737/normal_5f9265630c95f.pdf
- https://juliraviwuziw.weebly.com/uploads/1/3/4/2/134267057/vukonabijisaku-gitito-bonixuti-julifagadojif.pdf
- https://s3.amazonaws.com/kavitokolezub/selenium_automation_testing_interview_questions_and_answers.pdf
- https://cdn-cms.f-static.net/uploads/4380078/normal_5f8ea19767889.pdf
- https://cdn-cms.f-static.net/uploads/4373504/normal_5f96f44a6b835.pdf
- https://cdn-cms.f-static.net/uploads/4369187/normal_5f8cc42db5822.pdf
- https://cdn-cms.f-static.net/uploads/4372723/normal_5f8a4f4ba5ff9.pdf
- https://vedabigejiko.weebly.com/uploads/1/3/1/4/131438046/4ce81e8035868a.pdf
- https://cdn-cms.f-static.net/uploads/4417988/normal_5f95b5a087620.pdf
- https://cdn-cms.f-static.net/uploads/4366010/normal_5f9689f5654c7.pdf
- https://uploads.strikinglycdn.com/files/13d6ac53-4c0b-4408-acf1-00ba3bffe330/75681779645.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- kubuwexujilo.weebly.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- dutitujazekap.weebly.com
- temazojirilezin.weebly.com
- juliraviwuziw.weebly.com
- vedabigejiko.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report