MALICIOUS — 7021610.pdf
MALICIOUS — 7021610.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f57c9131d479031521a775e42d4b0dcf2f12673bb29927377bb06ba10bee6a0c - SHA-1:
4dda8a90f31e9e8fe8e7234e522f9f8a27f92ca6 - MD5:
64c8caa82f769a0fc30889ed55fc911c - ssdeep:
768:ygGzpDPKplkpKqKz6Z+Ag715BGocgiSYQuM/ekMUrP3v/0hEx26XCaiAWqjqJfR:vGFWplkpjKkub63Urfv8hExBXvpqJfR - TLSH:
T1DD337DF31077EC4C7AC79F13AEAA266D908AD748A132D7604588772DC4BC2BE7E00551 - Submitted as: 7021610.pdf
- File type: pdf · Size: 48344 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://tiwilofudux.weebly.com/uploads/1/3/1/6/131606348/8759e3d7ba2b.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=download%20the%20haves%20and%20the%20have%20nots, https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/bbf788f0.pdf, https://mapipuluzobeb.weebly.com/uploads/1/3/1/3/131398440/takedemitukuzi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=download%20the%20haves%20and%20the%20have%20nots
- https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/bbf788f0.pdf
- https://mapipuluzobeb.weebly.com/uploads/1/3/1/3/131398440/takedemitukuzi.pdf
- https://dojudiwoju.weebly.com/uploads/1/3/1/4/131406456/3694197.pdf
- https://tiwilofudux.weebly.com/uploads/1/3/1/6/131606348/8759e3d7ba2b.pdf
- https://fuparududewon.weebly.com/uploads/1/3/1/8/131856041/2bbe70a336.pdf
- https://pudegubazamase.weebly.com/uploads/1/3/1/1/131163945/73bad.pdf
- https://wozuwonasanava.weebly.com/uploads/1/3/1/4/131483955/aae2fc1b6c645.pdf
- https://vikumeniwexawud.weebly.com/uploads/1/3/0/9/130969440/c0c720d6032.pdf
- https://luwobidope.weebly.com/uploads/1/3/0/8/130814225/d3e2c515c.pdf
- https://lodirunesu.weebly.com/uploads/1/3/0/8/130874391/xetuvirabefun-tebura.pdf
- https://tenikekiso.weebly.com/uploads/1/3/0/7/130775729/gonag.pdf
- https://zadujemerumid.weebly.com/uploads/1/3/2/6/132695269/zejedexikejinakogake.pdf
- https://tisatazufewuvo.weebly.com/uploads/1/3/1/1/131163687/finajipot.pdf
- https://dofazodasi.weebly.com/uploads/1/3/0/8/130873943/1bc4307cb5d.pdf
- https://senobatupubem.weebly.com/uploads/1/3/1/4/131437889/5426e0baf5.pdf
- https://uploads.strikinglycdn.com/files/ca1220b3-3f9f-4e46-8419-4ebd7cc004f3/43782365737.pdf
- https://uploads.strikinglycdn.com/files/273e6c9c-12dc-47a2-9bae-db1a7b0995e3/jajadetemozodomuxodadasup.pdf
- https://uploads.strikinglycdn.com/files/28af412b-db77-4da0-bd36-c7cdd570d222/acura_ilx_owners_manual_2013.pdf
- https://cdn.shopify.com/s/files/1/0482/3256/2840/files/momiji_fruits_basket_2019_voice_actor.pdf
- https://cdn.shopify.com/s/files/1/0501/6810/3077/files/stretch_marks_tumblr.pdf
- https://cdn.shopify.com/s/files/1/0433/9888/9635/files/stylistic_analysis_to_kill_a_mockingbird_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0494/7142/2631/files/28264982699.pdf
- https://cdn.shopify.com/s/files/1/0268/8273/6309/files/43078451225.pdf
- https://cdn-cms.f-static.net/uploads/4365608/normal_5f86f69331d80.pdf
Embedded domains
- ggtraff.ru
- jamuseramomuf.weebly.com
- mapipuluzobeb.weebly.com
- dojudiwoju.weebly.com
- tiwilofudux.weebly.com
- fuparududewon.weebly.com
- pudegubazamase.weebly.com
- wozuwonasanava.weebly.com
- vikumeniwexawud.weebly.com
- luwobidope.weebly.com
- lodirunesu.weebly.com
- tenikekiso.weebly.com
- zadujemerumid.weebly.com
- tisatazufewuvo.weebly.com
- dofazodasi.weebly.com
- senobatupubem.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report