MALICIOUS — 5c156d7c21e74f.pdf
MALICIOUS — 5c156d7c21e74f.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
22b2b811446cb6400758ef362399cad2b9503116b815156835dc636155ed19f9 - SHA-1:
d02f9fe11adf1635018432b6e80e05fa400b19bd - MD5:
c42bcc92caebbda7c1addec3b17e2d13 - ssdeep:
768:SgGzpDEpfBRSaESLEjVhUxtcTVuwjbeqFTKgefsiqQu6L37ZeA5a163:PGFgpIYwjyseXsQuW37Zx5aE3 - TLSH:
T1C6329EF35093ED4C7B899B436DEB209A6489C7886136D790088C763DD4BC7BDBE60861 - Submitted as: 5c156d7c21e74f.pdf
- File type: pdf · Size: 44729 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/5648329.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=delonghi%20magnifica%20s%20plus%20manual, https://uploads.strikinglycdn.com/files/4e16f15d-27c2-450d-b7fc-eedc0a3d06cd/xijitefugofitizodesolez.pdf, https://uploads.strikinglycdn.com/files/88889721-05cc-48b7-a0ce-c3c90d22554a/8486873850.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=delonghi%20magnifica%20s%20plus%20manual
- https://uploads.strikinglycdn.com/files/4e16f15d-27c2-450d-b7fc-eedc0a3d06cd/xijitefugofitizodesolez.pdf
- https://uploads.strikinglycdn.com/files/88889721-05cc-48b7-a0ce-c3c90d22554a/8486873850.pdf
- https://uploads.strikinglycdn.com/files/5b71cfed-8e34-48d1-b3d5-0b481845274b/12673269684.pdf
- https://uploads.strikinglycdn.com/files/366c9e25-d001-467b-bf50-bc3fa4c48b9c/fufilaxunuvojowewejanowol.pdf
- https://xumogimunosu.weebly.com/uploads/1/3/1/6/131607683/a73cbec3e716.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/digokasawuj-jipamuputevuf.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/5648329.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/7775416.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/0c18874847f.pdf
- https://cdn.shopify.com/s/files/1/0478/0303/9903/files/presto_puzzle_page_ecology_word_search_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0266/8252/3834/files/sun_in_sign_language_asl.pdf
- https://cdn.shopify.com/s/files/1/0431/6764/5852/files/my_perspectives_book_grade_6.pdf
- https://cdn.shopify.com/s/files/1/0437/2011/4327/files/motorola_n136_bluetooth_headset_manual_free.pdf
- https://cdn.shopify.com/s/files/1/0494/2508/8679/files/18117767739.pdf
- https://site-1044255.mozfiles.com/files/1044255/dijazamananidinoku.pdf
- https://site-1040048.mozfiles.com/files/1040048/46768703334.pdf
- https://site-1036779.mozfiles.com/files/1036779/jivexomujufuxafo.pdf
- https://site-1037261.mozfiles.com/files/1037261/kipukoturusibolejeli.pdf
- https://site-1043442.mozfiles.com/files/1043442/24394932132.pdf
- https://cdn.shopify.com/s/files/1/0433/4351/1706/files/dadasanakizifupidodo.pdf
- https://cdn.shopify.com/s/files/1/0433/5891/2662/files/203901348.pdf
- https://cdn.shopify.com/s/files/1/0477/1525/4428/files/vanden_bussche_eric_armand.pdf
- https://cdn.shopify.com/s/files/1/0501/7508/2646/files/43313689459.pdf
- https://cdn.shopify.com/s/files/1/0486/2427/1525/files/14320353354.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- xumogimunosu.weebly.com
- keniwuki.weebly.com
- fijojonibiw.weebly.com
- jakedekokobara.weebly.com
- dutitujazekap.weebly.com
- cdn.shopify.com
- site-1044255.mozfiles.com
- site-1040048.mozfiles.com
- site-1036779.mozfiles.com
- site-1037261.mozfiles.com
- site-1043442.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report