MALICIOUS — 5ab305.pdf
MALICIOUS — 5ab305.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (77/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
473fab230993faae4363a92821b6a71d1b4502b3a973f36b5ff8a0c8f4d68785 - SHA-1:
214b687418f88543d545887023ecbd1de3690bef - MD5:
243c50d1d1f8b8f023fd431a5517993c - ssdeep:
768:9gGzpDFpqRQZ9Pi7GxPm3OOllu1AeQzB59LJwFN/9Axek/dt96aioRsTseeG:+GFBpM3plFBpwFNuYk/dxioRsTseeG - TLSH:
T111316CF36193ED8D3E8A6B03AEA7115D614AC749613796A004CC772CC5BC2FD6F10AA1 - Submitted as: 5ab305.pdf
- File type: pdf · Size: 41659 bytes
- Verdict: malicious (77/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 77/100 is the fusion of 5 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded link rated suspicious by URL analysis: https://sesorefamasupuv.weebly.com/uploads/1/3/1/0/131071262/zarubotitewel.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=ffxiv%20market%20board, https://uploads.strikinglycdn.com/files/791a71a6-c63a-4a0c-bbb1-105bf01ca3fb/33843213386.pdf, https://uploads.strikinglycdn.com/files/2d93b308-a609-46b9-9484-be716c00ebad/244327039.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=ffxiv%20market%20board
- https://uploads.strikinglycdn.com/files/791a71a6-c63a-4a0c-bbb1-105bf01ca3fb/33843213386.pdf
- https://uploads.strikinglycdn.com/files/2d93b308-a609-46b9-9484-be716c00ebad/244327039.pdf
- https://uploads.strikinglycdn.com/files/037f9b2e-9010-44e8-8677-4f45e5622cf3/kiwadoxutukuvezojexujuru.pdf
- https://uploads.strikinglycdn.com/files/980cdddb-7ae2-475c-b56d-b4b3d0945f3a/30086454090.pdf
- https://sesorefamasupuv.weebly.com/uploads/1/3/1/0/131071262/zarubotitewel.pdf
- https://duxixujojive.weebly.com/uploads/1/3/0/7/130739103/8938415.pdf
- https://nidixinaxob.weebly.com/uploads/1/3/0/7/130739699/9206f502e.pdf
- https://uploads.strikinglycdn.com/files/41f81832-49a5-4da9-8ca4-fb45adb9fd8c/fikikuzizawebozibadineru.pdf
- https://uploads.strikinglycdn.com/files/6eb7b418-eb0b-47b8-b88f-0e8ec54de95d/zotulisajov.pdf
- https://uploads.strikinglycdn.com/files/341af7d7-4dca-4c4c-bd08-b75fe788a5f9/rorakekopuz.pdf
- https://uploads.strikinglycdn.com/files/2bc48120-3ee7-4e21-8add-90f744b29d37/41385131570.pdf
- https://uploads.strikinglycdn.com/files/aa3918e9-d18f-478a-87e4-a963befc5765/befagixojejobadugubeg.pdf
- https://cdn-cms.f-static.net/uploads/4380393/normal_5f8dd336dcbf1.pdf
- https://cdn-cms.f-static.net/uploads/4381738/normal_5f8f76e340fbd.pdf
- https://cdn-cms.f-static.net/uploads/4376602/normal_5f8cc7b09f4d9.pdf
- https://cdn-cms.f-static.net/uploads/4388067/normal_5f8e86681f380.pdf
- https://cdn.shopify.com/s/files/1/0494/4255/4015/files/90710170816.pdf
- https://cdn.shopify.com/s/files/1/0436/4333/8912/files/tiwufinejexekotorajivebiw.pdf
- https://cdn.shopify.com/s/files/1/0460/7721/4884/files/7094316473.pdf
- https://cdn.shopify.com/s/files/1/0484/6996/7013/files/38907143060.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- sesorefamasupuv.weebly.com
- duxixujojive.weebly.com
- nidixinaxob.weebly.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report