MALICIOUS — kupovapifin-duduxufir-sadedowusi.pdf
MALICIOUS — kupovapifin-duduxufir-sadedowusi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0f7445ec84c70585a81e22e9c98b64511536aeebadbf6a4344e3a78ecc24e811 - SHA-1:
80edccf968364b4208dfdb462d89121a3887a5c5 - MD5:
539eb16f58d332ccb1949be90f213ae5 - ssdeep:
1536:uGFHpN26D5TAGpMi7TW5zZ+x2ucMAMgoOzl:XFHpNrD5FM2Wa8rMioo - TLSH:
T19D34ADF310E7ED9C7D8F6F139DAA159E6189D308917697504888BB2CD0FC9EDAE10860 - Submitted as: kupovapifin-duduxufir-sadedowusi.pdf
- File type: pdf · Size: 55420 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/9983102.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=cbse%2010th%20maths%20solution%20pdf, https://bezebaterizijir.weebly.com/uploads/1/3/1/3/131384714/regomeripo.pdf, https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/9983102.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=cbse%2010th%20maths%20solution%20pdf
- https://bezebaterizijir.weebly.com/uploads/1/3/1/3/131384714/regomeripo.pdf
- https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/9983102.pdf
- https://raxiruzaxulam.weebly.com/uploads/1/3/0/7/130738564/1466846.pdf
- https://degujipimisa.weebly.com/uploads/1/3/1/4/131453395/d01180669ae.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/9298899.pdf
- https://cdn-cms.f-static.net/uploads/4373757/normal_5f8e0add63eaf.pdf
- https://cdn-cms.f-static.net/uploads/4368985/normal_5f8bb9dc66aa0.pdf
- https://cdn-cms.f-static.net/uploads/4365655/normal_5f8722fea27c3.pdf
- https://uploads.strikinglycdn.com/files/e3a74ff6-1bc4-4dfd-a7e3-ee8575f68b6c/vesovusoredit.pdf
- https://uploads.strikinglycdn.com/files/e09b29a4-fa0d-4de7-a7c6-603c03e98c34/puwiper.pdf
- https://uploads.strikinglycdn.com/files/63abb479-6724-42af-ae8f-c3f4d4a6a827/60567262106.pdf
- https://uploads.strikinglycdn.com/files/661a8fda-ae3e-42e1-8bdc-3a5d9d4809ff/37002658111.pdf
- https://sabidodavo.weebly.com/uploads/1/3/1/4/131408103/e96a3fa2bef86.pdf
- https://goduvozimaku.weebly.com/uploads/1/3/1/3/131380582/8697108.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/4ce065df.pdf
- https://cdn.shopify.com/s/files/1/0501/4041/4133/files/miripirivawituzosijodo.pdf
- https://cdn.shopify.com/s/files/1/0432/3128/1312/files/49442909723.pdf
- https://cdn.shopify.com/s/files/1/0465/4311/0302/files/pearl_jam_stickman_svg.pdf
- https://cdn.shopify.com/s/files/1/0435/5247/3252/files/sulfur_hexafluoride_molar_mass.pdf
- https://vodiwisilob.weebly.com/uploads/1/3/2/6/132681054/74a5cfe963fba2.pdf
- https://wetuxabo.weebly.com/uploads/1/3/0/8/130873937/xomokisumisopava.pdf
- https://sozivutapadonen.weebly.com/uploads/1/3/1/1/131164462/6870774.pdf
- https://naxedomabaxa.weebly.com/uploads/1/3/1/6/131606472/817444.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- bezebaterizijir.weebly.com
- fodezamu.weebly.com
- raxiruzaxulam.weebly.com
- degujipimisa.weebly.com
- boguvetasitob.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- sabidodavo.weebly.com
- goduvozimaku.weebly.com
- tavumake.weebly.com
- cdn.shopify.com
- vodiwisilob.weebly.com
- wetuxabo.weebly.com
- sozivutapadonen.weebly.com
- naxedomabaxa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report