MALICIOUS — 5945091.pdf
MALICIOUS — 5945091.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fa87de9af505a06c603b1b5dd3caf81c2098fc84609480407771c8b7a45838af - SHA-1:
3990eb67e7ee71988eefaff44d797dac00ab8007 - MD5:
97f321df8d9d27b4bae70e3ec834f2bc - ssdeep:
768:7gGzpDLpQpJG44hxzqt/k5iLT0Qa470nFGhNdZy:EGFXpO94hxee5iH0Qf7WFqNdZy - TLSH:
T102319EF311E7DD8CBB879B03ADBB1059518AD3886127E720448C7A2CC8BC5BD7E50961 - Submitted as: 5945091.pdf
- File type: pdf · Size: 42610 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://pumowurunumig.weebly.com/uploads/1/3/2/7/132740285/dapakolun.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=r2d2%20interactive%20astromech%20droid%20instructions, https://uploads.strikinglycdn.com/files/f2d21bbb-4f8b-4fae-b9f3-84f3fcf9d50d/16648753704.pdf, https://uploads.strikinglycdn.com/files/4754e2a2-e735-43f5-ae57-eb0992875cbc/78300681645.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=r2d2%20interactive%20astromech%20droid%20instructions
- https://uploads.strikinglycdn.com/files/f2d21bbb-4f8b-4fae-b9f3-84f3fcf9d50d/16648753704.pdf
- https://uploads.strikinglycdn.com/files/4754e2a2-e735-43f5-ae57-eb0992875cbc/78300681645.pdf
- https://uploads.strikinglycdn.com/files/451e5538-e829-457e-8863-2c308705b846/18100672293.pdf
- https://uploads.strikinglycdn.com/files/3b804c10-d69a-44ac-94f5-46e0483bd321/bizivavisobojewub.pdf
- https://pumowurunumig.weebly.com/uploads/1/3/2/7/132740285/dapakolun.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/velimi.pdf
- https://kupugaxome.weebly.com/uploads/1/3/0/9/130969415/genakafas.pdf
- https://jeponiruwapin.weebly.com/uploads/1/3/0/7/130776483/lupasufevazetamu.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/1d1f8ecc085ca.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/sulusilalope-jobede.pdf
- https://site-1039259.mozfiles.com/files/1039259/91974588229.pdf
- https://site-1039649.mozfiles.com/files/1039649/59465239332.pdf
- https://site-1048568.mozfiles.com/files/1048568/66858832003.pdf
- https://site-1043279.mozfiles.com/files/1043279/99949455437.pdf
- https://uploads.strikinglycdn.com/files/f8a4d7a6-e89a-421d-8aa8-bda7453e7aea/gutoposojokapowemomikozos.pdf
- https://uploads.strikinglycdn.com/files/0bf5a334-3918-4a78-90aa-75ab10d156f8/73017674409.pdf
- https://uploads.strikinglycdn.com/files/842ef581-b711-4ca0-ba5b-061ea45d86ac/25001076916.pdf
- https://uploads.strikinglycdn.com/files/29051c7b-3ed1-430f-9501-688c899db782/31386628742.pdf
- https://uploads.strikinglycdn.com/files/190fc6a7-e825-4b98-82fa-601142ec012d/konivexemexev.pdf
- https://uploads.strikinglycdn.com/files/dbd9d534-550a-4fe7-a89f-94c31a53e00c/dalipenerulebebuvidutita.pdf
- https://uploads.strikinglycdn.com/files/359e53d3-82c3-4690-a5e0-216d79ad7273/kulutoda.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- pumowurunumig.weebly.com
- tavumake.weebly.com
- kupugaxome.weebly.com
- jeponiruwapin.weebly.com
- mogilifus.weebly.com
- genigudepa.weebly.com
- site-1039259.mozfiles.com
- site-1039649.mozfiles.com
- site-1048568.mozfiles.com
- site-1043279.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report