MALICIOUS — sizek.pdf
MALICIOUS — sizek.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a34137371e8e2713af137e0a858b10e1b48df8ab28e6fc29d58b1269999be2e8 - SHA-1:
9aa1a1ccda3be8e8e6d5f4d35166b01a2b44a2dd - MD5:
43e3fd5e53aac3fe21dac25618520fbf - ssdeep:
768:3gGzpDlpP93CUzufOwPuIFkh911FLbC8/cgeatELmzduG+PmO1RF2b:QGFhpPG8UgomzduP1RF2b - TLSH:
T1F7327DF35067DE8DB98BDB437EAA218C6049868D7122D7A105C87B6DC4782BF7F11820 - Submitted as: sizek.pdf
- File type: pdf · Size: 43986 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/97a52254-c29b-4a8d-a045-e9c9254881d7/58517609452.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=formulario%20de%20figuras%20geometricas%20area%20y%20perimetro%20y%20volumen, https://uploads.strikinglycdn.com/files/97a52254-c29b-4a8d-a045-e9c9254881d7/58517609452.pdf, https://uploads.strikinglycdn.com/files/a700834a-e755-4a4c-a290-89e96f9e97fb/verapiketuzo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=formulario%20de%20figuras%20geometricas%20area%20y%20perimetro%20y%20volumen
- https://uploads.strikinglycdn.com/files/97a52254-c29b-4a8d-a045-e9c9254881d7/58517609452.pdf
- https://uploads.strikinglycdn.com/files/a700834a-e755-4a4c-a290-89e96f9e97fb/verapiketuzo.pdf
- https://uploads.strikinglycdn.com/files/7180a8d1-cdf3-49eb-a118-96046700e7d6/zesaketubobabonawu.pdf
- https://uploads.strikinglycdn.com/files/8833a4cd-7fe4-4dbd-abce-73715daa308b/26111015704.pdf
- https://site-1039508.mozfiles.com/files/1039508/bijuwaxogofegume.pdf
- https://site-1043037.mozfiles.com/files/1043037/8670861765.pdf
- https://site-1043580.mozfiles.com/files/1043580/79982672720.pdf
- https://site-1038796.mozfiles.com/files/1038796/29085038201.pdf
- https://cdn.shopify.com/s/files/1/0431/3091/2934/files/throne_of_eldraine_prerelease_date.pdf
- https://cdn.shopify.com/s/files/1/0438/6127/8870/files/dragons_of_atlantis_mobile_guide.pdf
- https://cdn.shopify.com/s/files/1/0485/9451/8181/files/naxowovefu.pdf
- https://cdn.shopify.com/s/files/1/0433/5747/0874/files/tommy_hilfiger_shoe_size_guide.pdf
- https://uploads.strikinglycdn.com/files/5d68d7d4-561c-423d-bbf6-45ba586b68f9/pomajituvuzudezu.pdf
- https://uploads.strikinglycdn.com/files/a532ab45-2c8b-4fbd-a0dc-b051fe0e4f75/81821207913.pdf
- https://uploads.strikinglycdn.com/files/7a4fc8fb-03b4-4bd8-a6ed-61bfd7211457/zovukubemabi.pdf
- https://uploads.strikinglycdn.com/files/4636ba60-4c13-4df3-89c5-5adbab1dfcdb/42572164462.pdf
- https://uploads.strikinglycdn.com/files/febd0104-ea36-4ff2-8e19-edcd729ba5e7/76373263612.pdf
- https://cdn-cms.f-static.net/uploads/4369310/normal_5f87ce3e50279.pdf
- https://cdn-cms.f-static.net/uploads/4366047/normal_5f87f940b4126.pdf
- https://cdn-cms.f-static.net/uploads/4369904/normal_5f880fe8de2c0.pdf
- https://cdn-cms.f-static.net/uploads/4366029/normal_5f86fd4e4c524.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1039508.mozfiles.com
- site-1043037.mozfiles.com
- site-1043580.mozfiles.com
- site-1038796.mozfiles.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report