MALICIOUS — 982b0.pdf
MALICIOUS — 982b0.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e5b34e7c9c4aaf287bd14b8ecaaa7c214dab5d9e4d41e96379b2d5f4f8b9988d - SHA-1:
d22242ca535e8222c0b706485ee35c7bc3b3c030 - MD5:
ac825134a2c53b7719f5d05826106b9f - ssdeep:
768:qgGzpDnJpGcQEi5M8fVLNnSIUjY5YKS9KFJoCd0v0GbVgg/mzyXP:3GFDJpGmIUgY9CdntQm+XP - TLSH:
T1D5329DF310D3EC8C7B8A9F479DAB105D604DD6886136D6A0448C376ED5BCAEEBE00912 - Submitted as: 982b0.pdf
- File type: pdf · Size: 45406 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/1429013.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=how%20to%20thread%20a%20kenmore%20sewing%20machine%20model%20385, https://uploads.strikinglycdn.com/files/c1bdab5e-bbbf-4929-a108-c4f040880904/78976315614.pdf, https://uploads.strikinglycdn.com/files/f1de3d3c-676b-451b-8ca3-9c3a4052766b/46660392340.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=how%20to%20thread%20a%20kenmore%20sewing%20machine%20model%20385
- https://uploads.strikinglycdn.com/files/c1bdab5e-bbbf-4929-a108-c4f040880904/78976315614.pdf
- https://uploads.strikinglycdn.com/files/f1de3d3c-676b-451b-8ca3-9c3a4052766b/46660392340.pdf
- https://uploads.strikinglycdn.com/files/a3fc4801-2395-44af-a497-61d8ddf8e392/dewurolabopa.pdf
- https://uploads.strikinglycdn.com/files/83f9e07f-002c-4174-a8e6-30ec6c6586c9/watch_les_miserables_movie_online_fr.pdf
- https://cdn.shopify.com/s/files/1/0434/2772/5477/files/sadlier_vocabulary_workshop_level_f_unit_13_completing_the_sentence_answers.pdf
- https://cdn.shopify.com/s/files/1/0484/2956/4062/files/gre_probability_questions.pdf
- https://cdn.shopify.com/s/files/1/0497/3880/9498/files/chamberlain_clicker_universal_keyless_entry_instructions.pdf
- https://cdn.shopify.com/s/files/1/0499/9276/1499/files/49445652763.pdf
- https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/1429013.pdf
- https://firedisivimi.weebly.com/uploads/1/3/0/9/130969818/3ff63a3e0e0a0dd.pdf
- https://zesopupejilit.weebly.com/uploads/1/3/0/7/130738861/fokisitodidugu-nijebesudavit.pdf
- https://firedisivimi.weebly.com/uploads/1/3/0/9/130969818/1214108.pdf
- https://fewevivib.weebly.com/uploads/1/3/0/8/130813821/2137176.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/10610.pdf
- https://zegojipoxe.weebly.com/uploads/1/3/1/0/131069766/ef5858c355cfafe.pdf
- https://uploads.strikinglycdn.com/files/8f848f55-bd68-47cd-b614-ac54865fda96/milabajopusumajagobe.pdf
- https://uploads.strikinglycdn.com/files/8853e7fb-d2f0-4c50-860d-4979f3e598b2/93950403060.pdf
- https://uploads.strikinglycdn.com/files/48b4390a-cb84-4918-8819-3ca285c0d605/pugejed.pdf
- https://uploads.strikinglycdn.com/files/d8e977bf-3651-443c-b6a0-9ee7b8039cce/36725145411.pdf
- https://uploads.strikinglycdn.com/files/0b9f4729-cca0-4263-bac0-95aa025877eb/25763740412.pdf
- https://cdn.shopify.com/s/files/1/0434/8506/9477/files/32004461289.pdf
- https://cdn.shopify.com/s/files/1/0268/7582/2278/files/ap_environmental_science_practice_exam_college_board.pdf
- https://cdn.shopify.com/s/files/1/0462/6251/7909/files/65842497352.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- gevafitasib.weebly.com
- firedisivimi.weebly.com
- zesopupejilit.weebly.com
- fewevivib.weebly.com
- jakedekokobara.weebly.com
- zegojipoxe.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report