MALICIOUS — fba8604e519f6.pdf
MALICIOUS — fba8604e519f6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
050ab4f27a23005b3e39662055f98bc1b7c9c83f1da55e0b0a3535163e0c8a73 - SHA-1:
82c57115b7ff46ca4b71c19da917a86072cd2e55 - MD5:
5f1bcd9eaffb444a1b4225a440bd653d - ssdeep:
1536:XGFVpPxZY2jvzK3QTJHQPSM+QbEUJmKUDu/6IjEmTeGUDYb1ZmC60k7Sf1SC2:2FVpPxZY2jrGKmP+KEU0u/rTgDYXmC65 - TLSH:
T1DC39CFF3815BCD9C7D9A9B0399F711AC654ADA4E70319B60A488373CC4AC2BD7F60990 - Submitted as: fba8604e519f6.pdf
- File type: pdf · Size: 92243 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/ratot_muweliwamopoj.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=naruto%20boruto%20movie%20list, https://uploads.strikinglycdn.com/files/1363df7c-4170-4341-a58e-86fc36c8adc3/jujonigosine.pdf, https://uploads.strikinglycdn.com/files/34d3570d-580c-4af4-8fd2-49588ca50c4c/vasojivekofozakinapej.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=naruto%20boruto%20movie%20list
- https://uploads.strikinglycdn.com/files/1363df7c-4170-4341-a58e-86fc36c8adc3/jujonigosine.pdf
- https://uploads.strikinglycdn.com/files/34d3570d-580c-4af4-8fd2-49588ca50c4c/vasojivekofozakinapej.pdf
- https://uploads.strikinglycdn.com/files/2d91dc0f-25fe-40a9-8bed-e3d63b5e07db/9602127633.pdf
- https://uploads.strikinglycdn.com/files/c1cdb25c-9120-433a-9181-62e0dc961426/nizakit.pdf
- https://uploads.strikinglycdn.com/files/8b33785c-0b3c-45f2-8c15-5dc038da4e28/jubiv.pdf
- https://riragojefo.weebly.com/uploads/1/3/1/8/131857115/sipil.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/ratot_muweliwamopoj.pdf
- https://uploads.strikinglycdn.com/files/ef957e48-16e0-49ce-b552-519a9d2e670b/zemisikerotijoluloka.pdf
- https://uploads.strikinglycdn.com/files/88d03cc6-9609-4807-83ab-45cebb3303d2/roluwugewafiki.pdf
- https://uploads.strikinglycdn.com/files/e31ec80d-3dee-4d15-9a48-206796f6cda9/gamazajijulogeduz.pdf
- https://cdn-cms.f-static.net/uploads/4371786/normal_5f8a2237c5748.pdf
- https://cdn-cms.f-static.net/uploads/4376611/normal_5f8a77728a62e.pdf
- https://cdn.shopify.com/s/files/1/0431/3782/6973/files/jax_vs_riven_1v1.pdf
- https://cdn.shopify.com/s/files/1/0497/5063/8755/files/handbook_of_surface_and_colloid_chemistry.pdf
- https://cdn.shopify.com/s/files/1/0486/0752/7077/files/medical_certificate_for.pdf
- https://cdn.shopify.com/s/files/1/0428/8135/1839/files/concrete_diction_meaning.pdf
- https://bigogewoxof.weebly.com/uploads/1/3/0/7/130739615/zipivagagariju_gipupikukotif.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/dezidokezapovujiluwa.pdf
- https://rimesozarabef.weebly.com/uploads/1/3/1/6/131607712/mefilanube-sijajof-nuralenutuduz.pdf
- https://nijubalalo.weebly.com/uploads/1/3/1/4/131453980/12f53c87f87.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- riragojefo.weebly.com
- guwomenod.weebly.com
- cdn-cms.f-static.net
- cdn.shopify.com
- bigogewoxof.weebly.com
- tavumake.weebly.com
- rimesozarabef.weebly.com
- nijubalalo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report