MALICIOUS — 6292ad61c99dc02.pdf
MALICIOUS — 6292ad61c99dc02.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0e494b7a952ea1e6e959361567017e8bc667bfcab3cfd5b8dd5005fd9ce33c37 - SHA-1:
b393e15ff3fe6516abc262795518586113dfb09e - MD5:
9335ea5fe5f5dfefdc3248818bb2d17c - ssdeep:
768:BgGzpDWewn197Ule43Q/ZIFbd8ULaRxW6Cq7cmNK4rYz5gzw0y4O:yGF6eKed8BxW6Cq7ct4rYz5gz3y4O - TLSH:
T103328DF310EBED9C7A8BAB039DB71659548EC78C61239BA05488773CC47CABD6E14910 - Submitted as: 6292ad61c99dc02.pdf
- File type: pdf · Size: 45548 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/jixidused.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=nerf%20strongarm%20mod%20guide, https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/jixidused.pdf, https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/nakugirupexo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=nerf%20strongarm%20mod%20guide
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/jixidused.pdf
- https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/nakugirupexo.pdf
- https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/7462529.pdf
- https://kuwofepex.weebly.com/uploads/1/3/2/7/132740654/e73d6a239.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/9051060.pdf
- https://uploads.strikinglycdn.com/files/c00454ce-f3f1-42cb-bf42-2e6463f33645/dibigerejopixe.pdf
- https://cdn-cms.f-static.net/uploads/4372101/normal_5f89127ba79e8.pdf
- https://cdn-cms.f-static.net/uploads/4366628/normal_5f8afb8f9b9a1.pdf
- https://cdn-cms.f-static.net/uploads/4369645/normal_5f88b220a17b9.pdf
- https://cdn-cms.f-static.net/uploads/4366340/normal_5f8950bac73a2.pdf
- https://cdn-cms.f-static.net/uploads/4367017/normal_5f8aba6b58849.pdf
- https://uploads.strikinglycdn.com/files/c9476a55-3a0e-429e-b343-6274159f41c9/55178910049.pdf
- https://uploads.strikinglycdn.com/files/c1bea1f2-1e92-498e-bde8-f401c0b4f3c0/tamorinonosazevi.pdf
- https://uploads.strikinglycdn.com/files/7bd981ca-78ef-49ab-a84d-2ec822dedfe1/gajozuresukopixom.pdf
- https://uploads.strikinglycdn.com/files/44f99f12-27a8-4a24-8607-46a4c2b68264/bineken.pdf
- https://uploads.strikinglycdn.com/files/beb0f75c-fbbe-4944-a39d-c7cc7bfb1b11/58137419920.pdf
- https://uploads.strikinglycdn.com/files/69b2ffe0-3f35-44b2-8ca8-2392cc61ac96/43295042494.pdf
- https://uploads.strikinglycdn.com/files/2a0b8cfc-8ded-43f9-9164-450d960166e3/gomujof.pdf
- https://uploads.strikinglycdn.com/files/f0999290-db4b-4f18-8902-e490354b6c47/33137988605.pdf
- https://uploads.strikinglycdn.com/files/e9837794-c8d7-4be6-b7f4-37bd0a6535ed/98863114013.pdf
- https://cdn-cms.f-static.net/uploads/4368984/normal_5f8a4145e5150.pdf
- https://cdn-cms.f-static.net/uploads/4376098/normal_5f8b6158bae55.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- jatorogerujew.weebly.com
- vilukenuxe.weebly.com
- nudojafobedem.weebly.com
- kuwofepex.weebly.com
- zoxuzuxebexot.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report