MALICIOUS — a3603.pdf
MALICIOUS — a3603.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2d33468143624fa0d6e37a9a1c60c3945ff7ee2e1135a34f50a984afe0564945 - SHA-1:
8f0e3cabd30df6be737b0b4bbba8432e9f23f505 - MD5:
bc3298708c0dcf6cef89184ab9bdd805 - ssdeep:
768:sgGzpDipdgQDXpVLZMtDIXKuim9Ky5UgqIQId40k3AbAXkHqq:pGF+p5KTm9Kyig5nd40k3qAXGqq - TLSH:
T171316BF314E7DC4C7B8A9B43ADBB14AA608AC3885176DB90408C772CD5BC6BD7E50891 - Submitted as: a3603.pdf
- File type: pdf · Size: 39330 bytes
- Verdict: malicious (71/100)
Detections (2 of 53 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/f9007.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=amsco%20apush%202016%20multiple%20choice%20answer%20key, https://uploads.strikinglycdn.com/files/5dff7022-c69b-4028-baf7-4717b31c4367/90477087129.pdf, https://uploads.strikinglycdn.com/files/aa48a3df-7d6e-4f32-a148-af5e2a382b69/47260023476.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=amsco%20apush%202016%20multiple%20choice%20answer%20key
- https://uploads.strikinglycdn.com/files/5dff7022-c69b-4028-baf7-4717b31c4367/90477087129.pdf
- https://uploads.strikinglycdn.com/files/aa48a3df-7d6e-4f32-a148-af5e2a382b69/47260023476.pdf
- https://uploads.strikinglycdn.com/files/74c4d776-6260-4291-92d4-cd36c11429c7/69770417511.pdf
- https://uploads.strikinglycdn.com/files/4ba8cd45-67dc-484c-894f-54230bb4aac0/widejano.pdf
- https://uploads.strikinglycdn.com/files/509c6f8b-b3dc-4429-addf-582823302d6e/29520804196.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/f9007.pdf
- https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/devuxupujikeninaferi.pdf
- https://mabanopovofed.weebly.com/uploads/1/3/1/4/131453130/ce8a17394b.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/ce02014a20d.pdf
- https://cdn-cms.f-static.net/uploads/4366947/normal_5f87520cdf7d8.pdf
- https://cdn-cms.f-static.net/uploads/4366343/normal_5f8719d394f08.pdf
- https://cdn-cms.f-static.net/uploads/4366028/normal_5f88ff00a8469.pdf
- https://cdn-cms.f-static.net/uploads/4370088/normal_5f892e9874a37.pdf
- https://uploads.strikinglycdn.com/files/8441c538-2236-4b39-bb46-1cb66dcd77aa/zemunow.pdf
- https://uploads.strikinglycdn.com/files/cd229306-58b0-4cc8-896f-9a38ef0bba34/bomatijoxirowed.pdf
- https://uploads.strikinglycdn.com/files/c550dc49-a813-46f5-b573-6e4e3b371190/57097702363.pdf
- https://uploads.strikinglycdn.com/files/5b6be79e-d5ac-45d8-ba45-1fc4f7309ce3/gifigu.pdf
- https://uploads.strikinglycdn.com/files/a95fc684-3fa3-4c89-96ca-c60d77b59a9a/gapenijuridesezuwerifu.pdf
- https://uploads.strikinglycdn.com/files/f3b644b5-148d-43ed-be1f-40a71f49731a/68388447319.pdf
- https://uploads.strikinglycdn.com/files/edf19adb-7ed2-4770-9d8d-4d88a3c89d13/nirisigof.pdf
- https://uploads.strikinglycdn.com/files/faeb557e-feee-4e23-bfc5-c94ea7d91ab7/wikisuzutugadaneropobug.pdf
- https://cdn-cms.f-static.net/uploads/4370063/normal_5f89248aa046f.pdf
- https://cdn-cms.f-static.net/uploads/4369182/normal_5f888755ec365.pdf
- https://cdn-cms.f-static.net/uploads/4368242/normal_5f8949e91aed1.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- dutitujazekap.weebly.com
- fodezamu.weebly.com
- mabanopovofed.weebly.com
- bedizegoresupa.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report