MALICIOUS — 5a7f120226486.pdf
MALICIOUS — 5a7f120226486.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f4a36a6fd3019284ca8f45fe38b4ff1856ebc8f967a8a90d51caa18495be7edd - SHA-1:
18db94b0b7da87dc809e56726b391974fcf9e1eb - MD5:
8736bc76526a97b8db970f21637f447f - ssdeep:
768:SgGzpDnptJH5PhCW3V916bSj/XLf+6Bg8LrxXWBVmLJEEMRN7tmjwjX/3ckJ+Bh3:PGFDpiDAy8LrJtUN7QjwjXJQjoQ - TLSH:
T113329EF75097EC8C3A87A703ACA71229604EC78D7133A7A045887B2DD5BCABD7E50851 - Submitted as: 5a7f120226486.pdf
- File type: pdf · Size: 47319 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/wotareropajewub.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=lego%20duplo%20alphabet%20cards, https://cdn.shopify.com/s/files/1/0436/9675/0746/files/36053356558.pdf, https://cdn.shopify.com/s/files/1/0436/6788/2134/files/call_of_duty_mw3_mod_apk.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=lego%20duplo%20alphabet%20cards
- https://cdn.shopify.com/s/files/1/0436/9675/0746/files/36053356558.pdf
- https://cdn.shopify.com/s/files/1/0436/6788/2134/files/call_of_duty_mw3_mod_apk.pdf
- https://cdn.shopify.com/s/files/1/0466/3587/6517/files/train_sim_world_transpennine_manual.pdf
- https://cdn.shopify.com/s/files/1/0462/5763/5477/files/delta_band_saw_blades_59-1_2.pdf
- https://sisaseno.weebly.com/uploads/1/3/0/7/130776680/cfdfdd67.pdf
- https://misopiwulasi.weebly.com/uploads/1/3/1/8/131856666/5764964.pdf
- https://vimiwegom.weebly.com/uploads/1/3/0/7/130775837/pubufibezunekita.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/wotareropajewub.pdf
- https://cdn.shopify.com/s/files/1/0498/0834/3194/files/conflict_in_hamlet_essay.pdf
- https://cdn.shopify.com/s/files/1/0482/8518/8258/files/nepefun.pdf
- https://cdn.shopify.com/s/files/1/0496/0698/3829/files/bobibivomuzoruwemoxinu.pdf
- https://cdn.shopify.com/s/files/1/0492/0243/0118/files/9372957920.pdf
- https://cdn.shopify.com/s/files/1/0497/4827/9459/files/tertiary_carbon_vs_secondary_carbon.pdf
- https://lipowuripipu.weebly.com/uploads/1/3/1/3/131378852/e276efd25922.pdf
- https://baletepo.weebly.com/uploads/1/3/0/7/130776023/ledakegebomagi_likiguvafu.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/xizaxamuxive.pdf
- https://fadusoga.weebly.com/uploads/1/3/0/7/130739873/gajame.pdf
- https://uploads.strikinglycdn.com/files/8114e073-4ab3-493a-be69-323e97d48601/94131761909.pdf
- https://uploads.strikinglycdn.com/files/5fa8c7ed-61f7-4df2-8d85-90e7b37d403b/wavesorijedemufas.pdf
- https://uploads.strikinglycdn.com/files/5a470ff0-2ba2-4ca6-b130-f2b83dbed1ed/wowuto.pdf
- https://uploads.strikinglycdn.com/files/471b2e28-4537-470f-91bd-f9a37bf85f20/94070998019.pdf
- https://uploads.strikinglycdn.com/files/7afeb366-ace6-4cf4-8029-89acc977a35a/51463351608.pdf
- https://cdn-cms.f-static.net/uploads/4369311/normal_5f8954581ee30.pdf
- https://cdn-cms.f-static.net/uploads/4366388/normal_5f871c2278ee6.pdf
Embedded domains
- gettraff.ru
- cdn.shopify.com
- sisaseno.weebly.com
- misopiwulasi.weebly.com
- vimiwegom.weebly.com
- gimejexoxixaza.weebly.com
- lipowuripipu.weebly.com
- baletepo.weebly.com
- dutitujazekap.weebly.com
- fadusoga.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report