MALICIOUS — 26c4f6b1d143.pdf
MALICIOUS — 26c4f6b1d143.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a4bd53aaffd423c91ccdbc76cc1761020d29685146132203028965646171dcd8 - SHA-1:
fb49d3f6d75238b2f6a6437a58eaaf61c7ec91f9 - MD5:
b16044ef7aa3c6b5c4273072a17410d8 - ssdeep:
768:wgGzpDie0zHURFKt8GWZqA+z8j0qowIhwk+pZKWcCqyluvW:dGF2el+AAVhmyTCjuvW - TLSH:
T1AB327DF350A7ED4C3ACA6F0399AB019D654BC7896132979004D8672CC4BCAFD6F10A66 - Submitted as: 26c4f6b1d143.pdf
- File type: pdf · Size: 46531 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://rezizeme.weebly.com/uploads/1/3/0/7/130775554/79aca56bdf.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=adobe%20flash%20serial%20number, https://cdn-cms.f-static.net/uploads/4366374/normal_5f87fcb9c3e9d.pdf, https://cdn-cms.f-static.net/uploads/4366664/normal_5f873d80955e6.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=adobe%20flash%20serial%20number
- https://cdn-cms.f-static.net/uploads/4366374/normal_5f87fcb9c3e9d.pdf
- https://cdn-cms.f-static.net/uploads/4366664/normal_5f873d80955e6.pdf
- https://cdn-cms.f-static.net/uploads/4366305/normal_5f872b5692b12.pdf
- https://cdn-cms.f-static.net/uploads/4365560/normal_5f871ef0dd288.pdf
- https://cdn-cms.f-static.net/uploads/4365594/normal_5f8779ee9b551.pdf
- https://cdn-cms.f-static.net/uploads/4366976/normal_5f8730584e94d.pdf
- https://cdn-cms.f-static.net/uploads/4367937/normal_5f87bd906f3fd.pdf
- https://rezizeme.weebly.com/uploads/1/3/0/7/130775554/79aca56bdf.pdf
- https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/3966742.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/xereromejiv-koxozirusoror-moxonujis.pdf
- https://kekerisasil.weebly.com/uploads/1/3/0/7/130775365/16eb3cd9e365.pdf
- https://sibakixode.weebly.com/uploads/1/3/2/8/132814768/671e2e5e0646791.pdf
- https://turomanusogagi.weebly.com/uploads/1/3/1/4/131453559/5002527.pdf
- https://cdn.shopify.com/s/files/1/0435/2176/9627/files/holding_hands_drawing.pdf
- https://cdn.shopify.com/s/files/1/0465/3989/9039/files/mt_tamalpais_weather.pdf
- https://cdn.shopify.com/s/files/1/0494/7194/6919/files/43811865423.pdf
- https://cdn.shopify.com/s/files/1/0499/9525/1872/files/34606494362.pdf
- https://uploads.strikinglycdn.com/files/b9f5461b-0c86-4120-8975-801848923fdc/49608829774.pdf
- https://uploads.strikinglycdn.com/files/370a6739-40af-4d5f-8c95-2f4ec4559f30/poturitad.pdf
- https://uploads.strikinglycdn.com/files/e6889eba-10ca-42ba-b296-7f4f7d4708ea/52083102330.pdf
- https://uploads.strikinglycdn.com/files/aa9102d6-40ea-476a-ad11-1651175bc929/labomofitugisikuwuzo.pdf
- https://uploads.strikinglycdn.com/files/4d544c98-52ab-4c84-b8e3-0fd7ff0d9a48/gikif.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- rezizeme.weebly.com
- pigogokeda.weebly.com
- dutitujazekap.weebly.com
- kekerisasil.weebly.com
- sibakixode.weebly.com
- turomanusogagi.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report