MALICIOUS — 2042759.pdf
MALICIOUS — 2042759.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1613a3c0a035679ae614c62c2b36e4ccfbfe8c3f7d0497959630f0cbbecdce34 - SHA-1:
ffbe12c680600471dad326f9dba0958948d0a767 - MD5:
970c28c161602d608bedceb7c556b99e - ssdeep:
1536:6GF1p8qgdqkNoBfVN+lO+0LwFrS7naWzb:jF1pQABfDm0LwdSDay - TLSH:
T16B35AFF71097ED8CFB879B872EEB255A215A92896136D79014CC2B6CC1BC3BD3E10950 - Submitted as: 2042759.pdf
- File type: pdf · Size: 61659 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/bdfa22f.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=tevar%20songs%20download%20mymp3song, https://uploads.strikinglycdn.com/files/7df7f692-48e6-4f6d-bab3-72f94b00b513/98254711068.pdf, https://uploads.strikinglycdn.com/files/db82778b-30df-4e02-a595-daffbbb7ba99/maxor.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=tevar%20songs%20download%20mymp3song
- https://uploads.strikinglycdn.com/files/7df7f692-48e6-4f6d-bab3-72f94b00b513/98254711068.pdf
- https://uploads.strikinglycdn.com/files/db82778b-30df-4e02-a595-daffbbb7ba99/maxor.pdf
- https://uploads.strikinglycdn.com/files/a84ac3ee-5d2c-4505-a3f3-87d325e6ab41/nadodisuxijaxajapoz.pdf
- https://site-1040885.mozfiles.com/files/1040885/dokafome.pdf
- https://site-1039829.mozfiles.com/files/1039829/fivenirag.pdf
- https://site-1043833.mozfiles.com/files/1043833/sejufanake.pdf
- https://site-1038776.mozfiles.com/files/1038776/vutijaj.pdf
- https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/bdfa22f.pdf
- https://liwifaxuje.weebly.com/uploads/1/3/0/8/130874244/68fc228bb.pdf
- https://rabifupokuwu.weebly.com/uploads/1/3/1/1/131164250/c3a547f.pdf
- https://suwagapijewes.weebly.com/uploads/1/3/2/6/132682436/guvufixeda_dapalakazawasu_kogoriwuwod_nujaxemiwaton.pdf
- https://uploads.strikinglycdn.com/files/bd5fef5f-1759-403b-8cb7-c87eb54e2bfc/74985331079.pdf
- https://uploads.strikinglycdn.com/files/7e797c78-4f69-4848-ac6e-6b61f57a50ac/wuzopaluvugam.pdf
- https://site-1041693.mozfiles.com/files/1041693/gadanoj.pdf
- https://site-1037010.mozfiles.com/files/1037010/52789160814.pdf
- https://site-1042869.mozfiles.com/files/1042869/kurilofusasetujabosuw.pdf
- https://site-1043805.mozfiles.com/files/1043805/pajak_sarang_burung_walet.pdf
- https://site-1040203.mozfiles.com/files/1040203/canciones_faciles_para_guitarra_acustica.pdf
- https://cdn.shopify.com/s/files/1/0481/3796/1635/files/2001_volkswagen_passat_owners_manual.pdf
- https://cdn.shopify.com/s/files/1/0431/5850/3590/files/ariana_grande_cat_ear_headphones_review.pdf
- https://cdn.shopify.com/s/files/1/0428/4606/0710/files/sierra_national_forest_camping.pdf
- https://cdn.shopify.com/s/files/1/0478/0536/6431/files/29575686323.pdf
- https://cdn.shopify.com/s/files/1/0435/2642/2696/files/97720886173.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1040885.mozfiles.com
- site-1039829.mozfiles.com
- site-1043833.mozfiles.com
- site-1038776.mozfiles.com
- jaserasozupog.weebly.com
- liwifaxuje.weebly.com
- rabifupokuwu.weebly.com
- suwagapijewes.weebly.com
- site-1041693.mozfiles.com
- site-1037010.mozfiles.com
- site-1042869.mozfiles.com
- site-1043805.mozfiles.com
- site-1040203.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report