MALICIOUS — 5ee5b3c471.pdf
MALICIOUS — 5ee5b3c471.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
04710f0d8f7cbf9feab2a24829cb8d0f6818d13e2da4cf32a2c1d0842695136c - SHA-1:
c5627b40ce18a25cb0b9fab30bcde163b1e5e3d6 - MD5:
ea864bff1bae40a101e9224c1054a3e5 - ssdeep:
1536:aGFLgeFcD8CeD7izq0ZaHiN2vEDgvnoDG:DFLgeF+ssZWixs1 - TLSH:
T168349EF340A7FD4C7A8FEF43ADAA1159A14AD78D603296501988733CC4BC8BE6E11A50 - Submitted as: 5ee5b3c471.pdf
- File type: pdf · Size: 52331 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/7922058.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=math%20tutor%20resume%20sample%20pdf, https://cdn-cms.f-static.net/uploads/4366637/normal_5f8d3fd7cf3e6.pdf, https://cdn-cms.f-static.net/uploads/4378170/normal_5f8a18fa118c5.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=math%20tutor%20resume%20sample%20pdf
- https://cdn-cms.f-static.net/uploads/4366637/normal_5f8d3fd7cf3e6.pdf
- https://cdn-cms.f-static.net/uploads/4378170/normal_5f8a18fa118c5.pdf
- https://cdn-cms.f-static.net/uploads/4409393/normal_5f93008ce8574.pdf
- https://nipufijupetobug.weebly.com/uploads/1/3/1/4/131482996/6978290.pdf
- https://fonamajubeb.weebly.com/uploads/1/3/4/4/134474676/c75922b88c.pdf
- https://jikiwifapa.weebly.com/uploads/1/3/4/3/134338998/9414814.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/7922058.pdf
- https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/pewega_nejox_nutusotovifi.pdf
- https://cdn.shopify.com/s/files/1/0434/0056/0805/files/dandelion_girlfriend_witcher_3.pdf
- https://cdn.shopify.com/s/files/1/0485/3222/6203/files/tosagujenesivenugi.pdf
- https://cdn.shopify.com/s/files/1/0268/7628/1031/files/19947349615.pdf
- https://cdn.shopify.com/s/files/1/0494/1882/9991/files/lenovo_e490_specs.pdf
- https://cdn.shopify.com/s/files/1/0432/2253/2251/files/directv_orange_county_guide.pdf
- https://cdn.shopify.com/s/files/1/0483/6950/0309/files/xukiloxe.pdf
- https://cdn.shopify.com/s/files/1/0427/4061/3286/files/kafetomo.pdf
- https://cdn.shopify.com/s/files/1/0502/7073/2456/files/jinabatuletinevijuvesa.pdf
- https://pevugubak.weebly.com/uploads/1/3/2/7/132740457/papimi-nefewekapojerof-vorur.pdf
- https://kubupukadumu.weebly.com/uploads/1/3/1/3/131382740/7331740.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/8279107.pdf
- https://noxetetejiv.weebly.com/uploads/1/3/4/3/134391164/gegubilepozap.pdf
- https://jarapitoxedomel.weebly.com/uploads/1/3/1/4/131437170/fagazanula.pdf
- https://kivuligob.weebly.com/uploads/1/3/0/8/130874143/dalerumojexos.pdf
- https://jusujonolixutuw.weebly.com/uploads/1/3/1/3/131379247/5b355f93bd1.pdf
- https://wajiresejepo.weebly.com/uploads/1/3/0/7/130774962/6924245.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- nipufijupetobug.weebly.com
- fonamajubeb.weebly.com
- jikiwifapa.weebly.com
- fijojonibiw.weebly.com
- babikovinemixe.weebly.com
- cdn.shopify.com
- pevugubak.weebly.com
- kubupukadumu.weebly.com
- noxetetejiv.weebly.com
- jarapitoxedomel.weebly.com
- kivuligob.weebly.com
- jusujonolixutuw.weebly.com
- wajiresejepo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report