MALICIOUS — 3cbac7f.pdf
MALICIOUS — 3cbac7f.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b1892760b60750def88c94a81f635e00e29bd0a482437884de97077ebb539581 - SHA-1:
37945fa08828efdf766694455602ad9c04e27c43 - MD5:
3c7d38a1a64171fc1824ed610a919cb2 - ssdeep:
1536:aGFSpkQY6mMVN2A1Ga8c1n+/YuYBzY8MkrWFXJP:DFSpkQKMVoKx8cx+/YhZxMkUB - TLSH:
T14E35ADF350D7DD8D7996EB436CBB1215619AC7C86126C39084C86B2DC4FC6AEBF508A0 - Submitted as: 3cbac7f.pdf
- File type: pdf · Size: 59048 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/beparinunij.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=co-%20branding%20guidelines%20for%20a%20tourism%20company, https://uploads.strikinglycdn.com/files/345cc1fc-63ba-4e57-b4d9-a6ee87f650b4/42894829239.pdf, https://uploads.strikinglycdn.com/files/184a6fe4-b4b1-45dc-b189-b1474099e03f/xudimuvixefune.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=co-%20branding%20guidelines%20for%20a%20tourism%20company
- https://uploads.strikinglycdn.com/files/345cc1fc-63ba-4e57-b4d9-a6ee87f650b4/42894829239.pdf
- https://uploads.strikinglycdn.com/files/184a6fe4-b4b1-45dc-b189-b1474099e03f/xudimuvixefune.pdf
- https://uploads.strikinglycdn.com/files/99c6610c-8581-42b9-8420-1fccd7a57ec9/setobizakixejugudopireko.pdf
- https://uploads.strikinglycdn.com/files/08f08e1a-2574-4ac1-ad78-55929d8d5a0e/revava.pdf
- https://uploads.strikinglycdn.com/files/f1c756e5-2fc7-416b-a243-3148697fa072/119188883.pdf
- https://zesopupejilit.weebly.com/uploads/1/3/0/7/130738861/67f7767f9a8dfa.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/beparinunij.pdf
- https://zoveponezewuda.weebly.com/uploads/1/3/0/7/130738822/71adbf4216c214.pdf
- https://lasajiboz.weebly.com/uploads/1/3/1/3/131379041/fotuzax-tezoruvetibep.pdf
- https://uploads.strikinglycdn.com/files/75d8433d-2341-4316-a7d2-55596d7f47f9/5930271157.pdf
- https://uploads.strikinglycdn.com/files/75147b6d-a242-49f6-bd33-df74b6ba7da4/67238228432.pdf
- https://uploads.strikinglycdn.com/files/130f73ea-a277-441d-8f3c-e3e6855c00a4/16833972575.pdf
- https://site-1039731.mozfiles.com/files/1039731/zujinabide.pdf
- https://site-1039209.mozfiles.com/files/1039209/82150929137.pdf
- https://cdn-cms.f-static.net/uploads/4369653/normal_5f87fa7255f70.pdf
- https://cdn-cms.f-static.net/uploads/4369330/normal_5f87da5e2b3de.pdf
- https://cdn-cms.f-static.net/uploads/4366376/normal_5f873f7700d6b.pdf
- https://uploads.strikinglycdn.com/files/b22203b9-c703-48a8-ad46-709e4095c766/85987615569.pdf
- https://uploads.strikinglycdn.com/files/3af8e00c-3efe-4e17-b472-6f9a34f88106/saxejugilagiriwusi.pdf
- https://uploads.strikinglycdn.com/files/0c52f575-8bb3-4052-8c69-1fdc0f807d0e/20547044136.pdf
- https://uploads.strikinglycdn.com/files/337bb376-da20-4479-a504-af5a5a1bc32f/88223987522.pdf
- https://uploads.strikinglycdn.com/files/99c6b4b7-a466-4342-9692-bcaf222f083f/ruzemogixoralumonugepex.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- zesopupejilit.weebly.com
- jawasolasazilem.weebly.com
- zoveponezewuda.weebly.com
- lasajiboz.weebly.com
- site-1039731.mozfiles.com
- site-1039209.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report