MALICIOUS — 6041046.pdf
MALICIOUS — 6041046.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fabe95dc77113b97e10f83ebfb75527652a2bb64d782f74b3ada760a8f5af002 - SHA-1:
954be9c0e90f121aed3b19006638212b218a721b - MD5:
04ce0fe48af587701472f837515122cd - ssdeep:
1536:iGFKpLkZdx4SAq2eiq2pblXReMW0G0RI:bFKpK4m5ihpRReP5 - TLSH:
T117337DF35097ED8C7A8B9B83AAFB11AC614AD389B13297900488773CD47C5BD6F10A15 - Submitted as: 6041046.pdf
- File type: pdf · Size: 52048 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/wagejakofexaro_xerina.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=ora%C3%A7%C3%B5es%20subordinadas%20integrantes, https://site-1043613.mozfiles.com/files/1043613/44077925765.pdf, https://site-1040218.mozfiles.com/files/1040218/37359156038.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=ora%C3%A7%C3%B5es%20subordinadas%20integrantes
- https://site-1043613.mozfiles.com/files/1043613/44077925765.pdf
- https://site-1040218.mozfiles.com/files/1040218/37359156038.pdf
- https://site-1042987.mozfiles.com/files/1042987/fixed_end_moments_formula.pdf
- https://site-1039911.mozfiles.com/files/1039911/29170508430.pdf
- https://site-1039772.mozfiles.com/files/1039772/lebidonemuxibona.pdf
- https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/wagejakofexaro_xerina.pdf
- https://zoxaminajoge.weebly.com/uploads/1/3/1/6/131637873/doginoxitexeret.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/velowo_dakemolaku.pdf
- https://pavowojavujide.weebly.com/uploads/1/3/1/3/131398322/viluvenu_joxuvifadulaxi_funikumuvalusux_vadejinidenagi.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/e5bcd2697.pdf
- https://cdn.shopify.com/s/files/1/0499/4990/0955/files/13170912816.pdf
- https://cdn.shopify.com/s/files/1/0497/7842/6007/files/danaguzamifona.pdf
- https://cdn.shopify.com/s/files/1/0438/0046/1474/files/76164327378.pdf
- https://cdn.shopify.com/s/files/1/0483/4898/7545/files/nojegiwik.pdf
- https://cdn.shopify.com/s/files/1/0435/3097/7434/files/math_20d_ucsd_ali.pdf
- https://cdn.shopify.com/s/files/1/0481/1725/2249/files/age_of_war_3_hacked_unblocked_at_school.pdf
- https://cdn.shopify.com/s/files/1/0479/1769/5142/files/canon_in_egyptian_art.pdf
- https://cdn.shopify.com/s/files/1/0428/5949/5590/files/kiraduboki.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f873fbaacff6.pdf
- https://cdn-cms.f-static.net/uploads/4368226/normal_5f87cce63c25b.pdf
- https://cdn-cms.f-static.net/uploads/4366661/normal_5f87465f8e402.pdf
- https://site-1038590.mozfiles.com/files/1038590/nerevase.pdf
- https://site-1038772.mozfiles.com/files/1038772/59673101263.pdf
- https://site-1036958.mozfiles.com/files/1036958/dumipopedajexakinodukawin.pdf
Embedded domains
- ggtraff.ru
- site-1043613.mozfiles.com
- site-1040218.mozfiles.com
- site-1042987.mozfiles.com
- site-1039911.mozfiles.com
- site-1039772.mozfiles.com
- jaserasozupog.weebly.com
- zoxaminajoge.weebly.com
- genigudepa.weebly.com
- pavowojavujide.weebly.com
- gimejexoxixaza.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1038590.mozfiles.com
- site-1038772.mozfiles.com
- site-1036958.mozfiles.com
- site-1043765.mozfiles.com
- site-1042781.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report