MALICIOUS — e10fbc1dcc9c.pdf
MALICIOUS — e10fbc1dcc9c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b1d132585e0119e08e79b1882a0d381d0d2fa6739968047e05a9a3d86809c67b - SHA-1:
5435dc20bec21f5343ff6f811ec88067ed42e0f6 - MD5:
a500953559c8aca02f1765d62d30e5c5 - ssdeep:
768:wgGzpDFp8lFgQ77fUqtlSSxmadCY0HCez09n9+khIqHD/yULJ7YrCPs3FJqmqZ:dGFZp89Dmak09n9+kSqH7yUpKCPs3FJ2 - TLSH:
T116319EF71097EC9C399F6B53AEBF0169648AD789613292A004C9372CC07C6FD6F40962 - Submitted as: e10fbc1dcc9c.pdf
- File type: pdf · Size: 40718 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://rezizeme.weebly.com/uploads/1/3/0/7/130775554/7965169.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=8%20crayon%20box%20template, https://rezizeme.weebly.com/uploads/1/3/0/7/130775554/7965169.pdf, https://jizonuwuko.weebly.com/uploads/1/3/0/8/130814311/lomurujepidatam.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=8%20crayon%20box%20template
- https://rezizeme.weebly.com/uploads/1/3/0/7/130775554/7965169.pdf
- https://jizonuwuko.weebly.com/uploads/1/3/0/8/130814311/lomurujepidatam.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/tiladejonu.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/budokegigez.pdf
- https://cdn.shopify.com/s/files/1/0500/4912/2464/files/clasificacion_de_los_materiales_de_laboratorio_segun_su_fabricacion.pdf
- https://cdn.shopify.com/s/files/1/0431/7144/6939/files/sakemolasuna.pdf
- https://uploads.strikinglycdn.com/files/9faa51bf-3b02-4788-9b6a-10548579f3ae/vidizimavuzap.pdf
- https://uploads.strikinglycdn.com/files/3715893b-2813-4182-b078-ffacad15a936/96934028548.pdf
- https://uploads.strikinglycdn.com/files/52c005ae-87f6-4b4b-9a3e-b5912cc03754/giliralosuvagu.pdf
- https://cdn-cms.f-static.net/uploads/4370064/normal_5f8a6b1e3822a.pdf
- https://cdn-cms.f-static.net/uploads/4365575/normal_5f88b5108d03a.pdf
- https://cdn-cms.f-static.net/uploads/4366989/normal_5f882878337ec.pdf
- https://cdn-cms.f-static.net/uploads/4367281/normal_5f87cfb1b8e1e.pdf
- https://cdn-cms.f-static.net/uploads/4366055/normal_5f86ff929910a.pdf
- https://cdn.shopify.com/s/files/1/0482/1070/6619/files/gobesiludebolipawemaruwi.pdf
- https://cdn.shopify.com/s/files/1/0502/5700/2664/files/letugonixubimasorutavixol.pdf
- https://uploads.strikinglycdn.com/files/a97c27d9-e2f2-42c5-9b6d-72b0f33f45d4/tujeworirajufegakonuriwal.pdf
- https://uploads.strikinglycdn.com/files/fe81ac7c-c2a0-4488-943f-6a7a2940f487/meminunasinufazuxunabu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- rezizeme.weebly.com
- jizonuwuko.weebly.com
- guwomenod.weebly.com
- boguvetasitob.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report