MALICIOUS — todoleb.pdf
MALICIOUS — todoleb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fb2dee368d17e530b01bb6136826c9bee25e5843bb6c13f60c8ad33dedc8ea4f - SHA-1:
949cce637ea7eadc809b1d7a85241aa40a1293fd - MD5:
cb64e69a44b73a3f3ef0afab9b433e48 - ssdeep:
768:+gGzpDDHs79TEga1EBEEQ6dyCFK+1rx7/aVRE4YggGbtkqR5bQg:7GFfI9jayBEEQ6dWwgbYggGxfR5bQg - TLSH:
T17B32AFF340A7ED4C7AC5AF136EEA245D9196C7882133AB6048983B7DC17C3BC6E41A50 - Submitted as: todoleb.pdf
- File type: pdf · Size: 44586 bytes
- Verdict: malicious (75/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/ca2a1dfe-52d0-44e5-901c-40e9c7f737a3/guvejokisomonulusan.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=sintomas+de+la+caries+dental+pdf, http://files.devorenutrition.com/uploads/1/3/1/4/131438282/6638393.pdf, http://files.rbdist.com/uploads/1/3/1/8/131860938/juzitejifa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=sintomas+de+la+caries+dental+pdf
- http://files.devorenutrition.com/uploads/1/3/1/4/131438282/6638393.pdf
- http://files.rbdist.com/uploads/1/3/1/8/131860938/juzitejifa.pdf
- http://kotek.bostoncleaning.coop/uploads/1/3/2/7/132740412/2024594.pdf
- http://xobasewu.mindfulmusicacademy.com/uploads/1/3/1/3/131382982/xunek.pdf
- https://uploads.strikinglycdn.com/files/ca2a1dfe-52d0-44e5-901c-40e9c7f737a3/guvejokisomonulusan.pdf
- https://uploads.strikinglycdn.com/files/871c671f-f6e6-4210-913d-b2406878698e/xuvomexakegiduzuwo.pdf
- https://uploads.strikinglycdn.com/files/11e40f85-a754-46f2-b2cb-ece993995fb5/90790306266.pdf
- https://uploads.strikinglycdn.com/files/44e37f20-466a-4251-ad7e-395d82ae1722/foxomiwowuloku.pdf
- https://uploads.strikinglycdn.com/files/9f760ff5-eebb-4ad6-800e-cb54600a3289/94294055829.pdf
- https://site-1036848.mozfiles.com/files/1036848/refexu.pdf
- https://site-1036698.mozfiles.com/files/1036698/vetinesexanifowunu.pdf
- https://site-1037075.mozfiles.com/files/1037075/ribitezomuwefub.pdf
- http://files.ribreastfeeding.org/uploads/1/3/1/4/131437633/pupoz.pdf
- http://talovedu.stpaulsellicottville.com/uploads/1/3/1/3/131384013/lutuwabiwekaze_xovozed_geragevezimugep_mebukonaj.pdf
- http://files.annegabriele.com/uploads/1/3/1/4/131406506/23427572dca46.pdf
- http://vuzapa.trickedoutewe.com/uploads/1/3/1/4/131406676/niguripuzon.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- files.devorenutrition.com
- files.rbdist.com
- xobasewu.mindfulmusicacademy.com
- uploads.strikinglycdn.com
- site-1036848.mozfiles.com
- site-1036698.mozfiles.com
- site-1037075.mozfiles.com
- files.ribreastfeeding.org
- talovedu.stpaulsellicottville.com
- files.annegabriele.com
- vuzapa.trickedoutewe.com
- www.w3.org
- purl.org
- ns.adobe.com
- kotek.bostoncleaning.coop
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report