MALICIOUS — 05209.pdf
MALICIOUS — 05209.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
33d8ae1e5345a2b1df4db73e53cd252102fbe7404ba191b777ee9188ba97574d - SHA-1:
bba24f3c8a16f7354fa7074da2ea59ebdd5bd67b - MD5:
0498c4a9bef6b962fe6830a4cfe3a1ab - ssdeep:
1536:pGFlp5+dhAnNPvLI1HHT8TQLWY3HNkYdX:8Flp5LnNPvq4TQZNky - TLSH:
T192339FF790B7ED4C3A8B6B437AA6159A6185C6CD6123D7A044CC772CC1BC6FE6E00A11 - Submitted as: 05209.pdf
- File type: pdf · Size: 52103 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://rezizeme.weebly.com/uploads/1/3/0/7/130775554/aaa1b366bd7fe.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=star%20wars%20mod%201.%207.%2010, https://rezizeme.weebly.com/uploads/1/3/0/7/130775554/aaa1b366bd7fe.pdf, https://xojisige.weebly.com/uploads/1/3/1/6/131637148/dolunabijosim.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=star%20wars%20mod%201.%207.%2010
- https://rezizeme.weebly.com/uploads/1/3/0/7/130775554/aaa1b366bd7fe.pdf
- https://xojisige.weebly.com/uploads/1/3/1/6/131637148/dolunabijosim.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/1978709.pdf
- https://cdn.shopify.com/s/files/1/0437/3377/8597/files/parker_car_guide_facts_and_figures.pdf
- https://cdn.shopify.com/s/files/1/0479/0114/7302/files/morrowind_beginners_guide_reddit.pdf
- https://cdn.shopify.com/s/files/1/0431/0456/7450/files/bio_clean_drain_cleaner_reviews.pdf
- https://cdn.shopify.com/s/files/1/0487/7382/4678/files/toram_pet_skill_guide.pdf
- https://cdn.shopify.com/s/files/1/0477/5247/8876/files/52920255837.pdf
- https://cdn.shopify.com/s/files/1/0435/7236/3432/files/bigutafuwerar.pdf
- https://loguxofe.weebly.com/uploads/1/3/0/7/130775118/bc44ba.pdf
- https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/fewit-latafele.pdf
- https://jeponiruwapin.weebly.com/uploads/1/3/0/7/130776483/powuwenalapufaxusun.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/jibigamefomoni.pdf
- https://uploads.strikinglycdn.com/files/d50440c7-38f5-41a2-8f93-8c73ae7fe939/lagepodufi.pdf
- https://uploads.strikinglycdn.com/files/8d76cfc7-ae41-4488-b7e3-e71cce0c63a7/parewenenu.pdf
- https://site-1041501.mozfiles.com/files/1041501/gekojabomumifinazo.pdf
- https://site-1043925.mozfiles.com/files/1043925/bibewifizavuzujafe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- rezizeme.weebly.com
- xojisige.weebly.com
- boguvetasitob.weebly.com
- cdn.shopify.com
- loguxofe.weebly.com
- sesuwulot.weebly.com
- jeponiruwapin.weebly.com
- fijojonibiw.weebly.com
- uploads.strikinglycdn.com
- site-1041501.mozfiles.com
- site-1043925.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report