MALICIOUS — 86500298820.pdf
MALICIOUS — 86500298820.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3d9d812ac0d4a7ffa3dee60752a972e3c11dbe7761180a35b81161d7e2965c52 - SHA-1:
bd22f696b1c1e3ff79f05ada8b15bee687ef442d - MD5:
b29bfa0c50af32798e8a517b4cf56431 - ssdeep:
768:MgGzpDG/k0P2DIWmx26ZRoIFkZcm5eHfHhdN4bpisgEn8WxYZmIgpuN0cq0:JGFi/kaRZRo23G7t8WqAuN0cq0 - TLSH:
T11033BFF714ABDD8C76C79707AEA308646149C38D6233A79408C8762DC4BCBBD7E50A60 - Submitted as: 86500298820.pdf
- File type: pdf · Size: 50288 bytes
- Verdict: malicious (75/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/94ce3544-abe9-46e7-9293-30d6498096bc/bovuzikudopizufeferufij.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=stardew+valley+gay+mods, https://uploads.strikinglycdn.com/files/94ce3544-abe9-46e7-9293-30d6498096bc/bovuzikudopizufeferufij.pdf, https://uploads.strikinglycdn.com/files/70c9c3f8-d9e2-4791-a6ba-26d036d9c32e/47644765695.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=stardew+valley+gay+mods
- https://uploads.strikinglycdn.com/files/94ce3544-abe9-46e7-9293-30d6498096bc/bovuzikudopizufeferufij.pdf
- https://uploads.strikinglycdn.com/files/70c9c3f8-d9e2-4791-a6ba-26d036d9c32e/47644765695.pdf
- https://uploads.strikinglycdn.com/files/3572d112-7f68-48ac-8b53-c9412ac63da1/rujut.pdf
- https://uploads.strikinglycdn.com/files/32c43d7a-8d65-4231-9dc3-3dcb836eda4b/14828644102.pdf
- https://uploads.strikinglycdn.com/files/a73ede1e-1c4f-4387-aa08-7aaa5fb961ca/komorogafupupatoxomag.pdf
- https://cdn.shopify.com/s/files/1/0431/0011/0999/files/rugby_songs_youtube.pdf
- https://cdn.shopify.com/s/files/1/0498/7096/2843/files/dokofajomokexuridewu.pdf
- https://cdn.shopify.com/s/files/1/0437/1320/0278/files/pukujuwarekasaga.pdf
- https://cdn.shopify.com/s/files/1/0484/2887/5934/files/genesamigivewunezuzo.pdf
- https://site-1038595.mozfiles.com/files/1038595/46571417271.pdf
- https://site-1042666.mozfiles.com/files/1042666/suzisukavotetuzalad.pdf
- https://site-1041939.mozfiles.com/files/1041939/dupilab.pdf
- https://site-1039419.mozfiles.com/files/1039419/42165110502.pdf
- https://site-1037096.mozfiles.com/files/1037096/42909125235.pdf
- https://uploads.strikinglycdn.com/files/440d3561-2347-4ff5-bde3-22de4cf332a3/55837452644.pdf
- https://uploads.strikinglycdn.com/files/8dbf0b21-d96f-4c61-af23-8265c516942c/10243870655.pdf
- https://uploads.strikinglycdn.com/files/8beea885-3744-4b31-bb7a-84be3c6c9943/14352229111.pdf
- https://uploads.strikinglycdn.com/files/ca94166a-b6e3-4a62-abac-2f2e454b0ceb/90251839124.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1038595.mozfiles.com
- site-1042666.mozfiles.com
- site-1041939.mozfiles.com
- site-1039419.mozfiles.com
- site-1037096.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report