MALICIOUS — sekagibofomimopo.pdf
MALICIOUS — sekagibofomimopo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b90491b5296977c84590d3788975d9a51246f5963db02694cc2cbdd39092c43a - SHA-1:
70b136d6d65354e8596c181088c548a3361e72c6 - MD5:
10d9d0d494a7649ea627c5a8b8a80b29 - ssdeep:
768:MgGzpD5pBfJdutNqDMrtr/x2Ii4otm0YGUMFUGTRO+8bGMkBqzZCB/DG9/nB+v2f:JGF9pBeZLi4Im0WATRO+TbqzZg6VB++f - TLSH:
T17F33AEF350A7DD8C3ACB6B07A9B60069248AC78C602797E049C837ADC97C5EE7D10961 - Submitted as: sekagibofomimopo.pdf
- File type: pdf · Size: 48633 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/c3a79143-fd5d-49dd-9e52-c28bb083c079/kikabefidogonakagisesug.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=pokemon%20xy%20gba%20roms, https://uploads.strikinglycdn.com/files/9d411197-22a5-45f0-863b-bdc03cf89cb1/dinofuremonezeriz.pdf, https://uploads.strikinglycdn.com/files/be0dc1d9-2bce-4a46-b267-618b3d0043ad/safonavajomogi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=pokemon%20xy%20gba%20roms
- https://uploads.strikinglycdn.com/files/9d411197-22a5-45f0-863b-bdc03cf89cb1/dinofuremonezeriz.pdf
- https://uploads.strikinglycdn.com/files/be0dc1d9-2bce-4a46-b267-618b3d0043ad/safonavajomogi.pdf
- https://uploads.strikinglycdn.com/files/c3a79143-fd5d-49dd-9e52-c28bb083c079/kikabefidogonakagisesug.pdf
- https://uploads.strikinglycdn.com/files/c9e9bb04-a69b-4f37-ba73-d302b0a057f9/8765002322.pdf
- https://cdn.shopify.com/s/files/1/0438/0898/1153/files/new_haven_bmv_branch.pdf
- https://uploads.strikinglycdn.com/files/c88bdf67-ad32-462e-8fa6-75039cdab0cb/66608943652.pdf
- https://uploads.strikinglycdn.com/files/23430390-5bc3-4890-a36c-bf24e1bbcedb/zotowi.pdf
- https://uploads.strikinglycdn.com/files/23bd4175-f5a3-4c4e-a913-3fc1a66ab639/budeterixe.pdf
- https://cdn-cms.f-static.net/uploads/4366327/normal_5f874c4a157e7.pdf
- https://cdn-cms.f-static.net/uploads/4367667/normal_5f88f34ee0d97.pdf
- https://cdn-cms.f-static.net/uploads/4370052/normal_5f88bc62674bf.pdf
- https://cdn-cms.f-static.net/uploads/4366381/normal_5f87fa8b1ed1b.pdf
- https://cdn-cms.f-static.net/uploads/4366331/normal_5f87630071a63.pdf
- https://site-1037893.mozfiles.com/files/1037893/petudebowo.pdf
- https://site-1037275.mozfiles.com/files/1037275/kusixikuwidapabixotamab.pdf
- https://cdn.shopify.com/s/files/1/0268/7962/3340/files/pioneer_gm_5400t_manual.pdf
- https://cdn.shopify.com/s/files/1/0480/7832/3876/files/dude_and_zombies_cheats.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1037893.mozfiles.com
- site-1037275.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report