MALICIOUS — temeba.pdf
MALICIOUS — temeba.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e2c6e064473ed48c5cdadae5a13775808d0d1c78d280a5a5f83bc987d491d9f4 - SHA-1:
e21ccfc51e29054adc9ad1e620dd23bb8a84904f - MD5:
45ebbcb6efd1815f5c29c8b5edf8c076 - ssdeep:
768:xgGzpDXpm46VPbs2fAn18OyDkkuUGakZoyJYvk2Cw9udxrnMVg1K:CGFrpmfYkuUFkCyyD9uZMVg1K - TLSH:
T176317CF31097ED0C7A878B13ADB71AAA608DC388613797A0448C373D94BC67E7E11961 - Submitted as: temeba.pdf
- File type: pdf · Size: 42714 bytes
- Verdict: malicious (75/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/8925184.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=craftsman%20easyfire%20electric%20staple%20gun%20manual, https://cdn-cms.f-static.net/uploads/4380403/normal_5f90343f2a37e.pdf, https://cdn-cms.f-static.net/uploads/4366003/normal_5f871fd248885.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=craftsman%20easyfire%20electric%20staple%20gun%20manual
- https://cdn-cms.f-static.net/uploads/4380403/normal_5f90343f2a37e.pdf
- https://cdn-cms.f-static.net/uploads/4366003/normal_5f871fd248885.pdf
- https://cdn-cms.f-static.net/uploads/4366958/normal_5f87c3b38b302.pdf
- https://cdn-cms.f-static.net/uploads/4366622/normal_5f874a14a4067.pdf
- https://cdn-cms.f-static.net/uploads/4368235/normal_5f94d12b396cc.pdf
- https://fadusoga.weebly.com/uploads/1/3/0/7/130739873/408124.pdf
- https://laguvibokabab.weebly.com/uploads/1/3/4/3/134383318/damepefaxedi_vazisisapuxo.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/8925184.pdf
- https://mabanopovofed.weebly.com/uploads/1/3/1/4/131453130/lorowafokujaragelote.pdf
- https://zevodajiwagadiz.weebly.com/uploads/1/3/4/3/134340874/nodesowumuwuxug-nanenuwogeg-mogozewemoka.pdf
- https://vuzevarezevarot.weebly.com/uploads/1/3/0/7/130740461/larurozinuko-jasiwopima.pdf
- https://dirigesibujov.weebly.com/uploads/1/3/0/9/130969991/zudaleribezulis_ribaxu_zudovozixezuviw_wegavuwuma.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/e7a433bb9f.pdf
- https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/4a90eaba6.pdf
- https://cdn-cms.f-static.net/uploads/4376629/normal_5f8ed3a83c9fe.pdf
- https://cdn-cms.f-static.net/uploads/4420765/normal_5f965fb41b5b7.pdf
- https://cdn-cms.f-static.net/uploads/4390995/normal_5f965573d54d2.pdf
- https://cdn-cms.f-static.net/uploads/4375509/normal_5f93f0931fd77.pdf
- https://uploads.strikinglycdn.com/files/15a38d95-ca4c-43ad-a674-96c24f2f9d5e/kukivobi.pdf
- https://uploads.strikinglycdn.com/files/edcb9c21-c013-4804-9a5e-b96420567cd4/xirinorotiguxiz.pdf
- https://uploads.strikinglycdn.com/files/da5a0851-2fba-4c42-b6cd-aff3af7cdf06/derailed_movie_300mb.pdf
- https://uploads.strikinglycdn.com/files/30db95e8-88f6-495c-864a-b3c18e5bcbb7/51129362398.pdf
- https://uploads.strikinglycdn.com/files/e7cbcad7-c2c3-4bc6-90cd-7ba79df93f4e/mary_higgins_clark_movies_on_netflix.pdf
- https://uploads.strikinglycdn.com/files/c9a64b5a-c2ad-41c5-b37e-7890113c001e/92816841007.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- fadusoga.weebly.com
- laguvibokabab.weebly.com
- vuxozajuje.weebly.com
- mabanopovofed.weebly.com
- zevodajiwagadiz.weebly.com
- vuzevarezevarot.weebly.com
- dirigesibujov.weebly.com
- mogilifus.weebly.com
- jamuseramomuf.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report