MALICIOUS — 53ee3930ad6ef6.pdf
MALICIOUS — 53ee3930ad6ef6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
330bc0b7630d6497706fa1882b7d01c2f4cd6601be6ae835e7a7ca41c2000c98 - SHA-1:
548f59048571f31e87c51ff8abc41717676127c9 - MD5:
91fbc9a83d69455053d8d53c91a72bde - ssdeep:
768:YxgGzpD+pV0C5xn/e7ryRrXerp/5qA4Wsf8ROp12+MefOTio0RWFvEVPM4an:rGFCpm7zif8Rm12+MgO2eFYWn - TLSH:
T1FB327BF340A7DD8C7A8FAB43ADAB4499659AC3856137C76014CC7B6CC4B86AD7F10860 - Submitted as: 53ee3930ad6ef6.pdf
- File type: pdf · Size: 43369 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/4867245.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=playboy%202015%20collectors%20edition%20pdf, https://cdn-cms.f-static.net/uploads/4372072/normal_5f8af8c889ea3.pdf, https://cdn-cms.f-static.net/uploads/4366316/normal_5f87d2edb2ff2.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=playboy%202015%20collectors%20edition%20pdf
- https://cdn-cms.f-static.net/uploads/4372072/normal_5f8af8c889ea3.pdf
- https://cdn-cms.f-static.net/uploads/4366316/normal_5f87d2edb2ff2.pdf
- https://cdn-cms.f-static.net/uploads/4382430/normal_5f8ff8f753320.pdf
- https://uploads.strikinglycdn.com/files/5484fbd5-782b-4e4d-99ef-1ff09e813b59/viwevasamuvuwuwabulogepis.pdf
- https://uploads.strikinglycdn.com/files/fd1fd9d7-97f2-4fdb-9d50-ce4b87c02c35/99608884590.pdf
- https://uploads.strikinglycdn.com/files/4f232d2d-199e-4072-8b05-de3bf045fb87/8371491681.pdf
- https://uploads.strikinglycdn.com/files/b10a9880-7e49-46f4-8a27-c6d7ae03694f/63398903774.pdf
- https://uploads.strikinglycdn.com/files/447b271a-f115-4ba2-9a36-efc111d7ba78/pifimalugomorejevavu.pdf
- https://s3.amazonaws.com/memul/mazaboz.pdf
- https://s3.amazonaws.com/henghuili-files2/lithium_ion_battery_construction_and_working.pdf
- https://s3.amazonaws.com/tetazino/sizigim.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/4867245.pdf
- https://lagukekejase.weebly.com/uploads/1/3/0/8/130815031/931546.pdf
- https://xikosenazegan.weebly.com/uploads/1/3/0/7/130739601/4058633.pdf
- https://cdn-cms.f-static.net/uploads/4380523/normal_5f90b306a7db5.pdf
- https://cdn-cms.f-static.net/uploads/4384470/normal_5f8f8a14230c4.pdf
- https://cdn-cms.f-static.net/uploads/4366034/normal_5f8700c206f99.pdf
- https://cdn-cms.f-static.net/uploads/4367271/normal_5f8c8f14804cc.pdf
- https://cdn-cms.f-static.net/uploads/4366665/normal_5f9107a56ea7c.pdf
- https://cdn.shopify.com/s/files/1/0432/9383/5432/files/acr_guidelines_for_rheumatoid_arthritis_2020.pdf
- https://cdn.shopify.com/s/files/1/0268/8427/6415/files/jopenabetuxorofivuvawo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- s3.amazonaws.com
- gimejexoxixaza.weebly.com
- lagukekejase.weebly.com
- xikosenazegan.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report