MALICIOUS — 23afb94a585.pdf
MALICIOUS — 23afb94a585.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
dd7dd457a5c4bd93e586f0cef95e1c653d130733eca37873bc52e120f0f615e2 - SHA-1:
262bedf01cdd30e45888dc356c4d0058d06fb40f - MD5:
f1585a66dbdf93d414a14fe6d89e3806 - ssdeep:
768:DgGzpDppg3r3kHu0WzmCWAxMTPbA7yqwLAeBxhez4tVfaOTIcUAVeQ6aD:8GFNpRGmeMHW07eMnfaqR1VeQ6aD - TLSH:
T178318DF71097ED8C768A6F17AEAB105D618AC3893136C670448C7B2CC47C6FD6E50A61 - Submitted as: 23afb94a585.pdf
- File type: pdf · Size: 43245 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://tekegalesi.weebly.com/uploads/1/3/0/7/130740489/9251850.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=greenlight%20capital%20q3%202019%20letter%20pdf, https://tekegalesi.weebly.com/uploads/1/3/0/7/130740489/9251850.pdf, https://damijuvik.weebly.com/uploads/1/3/1/3/131381376/xofasimuvirit.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=greenlight%20capital%20q3%202019%20letter%20pdf
- https://tekegalesi.weebly.com/uploads/1/3/0/7/130740489/9251850.pdf
- https://damijuvik.weebly.com/uploads/1/3/1/3/131381376/xofasimuvirit.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/sidobojugonuxexoz.pdf
- https://cdn-cms.f-static.net/uploads/4380223/normal_5f8c603cf01eb.pdf
- https://cdn-cms.f-static.net/uploads/4376629/normal_5f8ed6cf4f917.pdf
- https://cdn.shopify.com/s/files/1/0501/1380/6486/files/sotuxit.pdf
- https://cdn.shopify.com/s/files/1/0433/9302/4149/files/93589571804.pdf
- https://uploads.strikinglycdn.com/files/73b3d2d7-d0c8-4352-ba5e-712648027a63/angel_with_black_wings_meaning.pdf
- https://uploads.strikinglycdn.com/files/205cb1ec-0a45-4d1c-8646-4d91609d707e/guroz.pdf
- https://uploads.strikinglycdn.com/files/607a1240-02b1-46fb-bf7d-ec066ea6db8e/statement_of_purpose_for_masters_in_public_policy.pdf
- https://uploads.strikinglycdn.com/files/ce0f34d3-5b34-4cf9-94c7-76a6e98143cd/h2co_intermolecular_forces.pdf
- https://uploads.strikinglycdn.com/files/287e62c4-b536-4ad5-8a03-908edca1a84e/dd_toure_neman.pdf
- https://cdn.shopify.com/s/files/1/0439/4637/7374/files/iphone_x_gestures_android_xda.pdf
- https://cdn.shopify.com/s/files/1/0477/8298/5887/files/51803159788.pdf
- https://cdn.shopify.com/s/files/1/0492/2199/2599/files/android_sdk_aapt.exe_download.pdf
- https://uploads.strikinglycdn.com/files/5b862263-f90e-44bb-a49b-9c9a34851e0c/jopinevuwaguwunalupotag.pdf
- https://uploads.strikinglycdn.com/files/40fd8c51-4703-403b-bcf0-67bff8ba5bbf/zodejababumunivunozusuj.pdf
- https://uploads.strikinglycdn.com/files/a3973253-8d7b-4c5f-809a-c1e0e6de028d/21535326219.pdf
- https://uploads.strikinglycdn.com/files/06bfd8fb-2426-4994-aeb2-12aa5157bb15/sinabusuwosatetalebir.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- tekegalesi.weebly.com
- damijuvik.weebly.com
- dutitujazekap.weebly.com
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report