MALICIOUS — 6363393.pdf
MALICIOUS — 6363393.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3618df1201434cc6a068a830ba96d1de5bd6d308421c2b3ecdda972ec158a6fe - SHA-1:
5e456ecf3d96e83461ed82ad5cd225e15af56360 - MD5:
dc4d0945fe03377c7151e10e03c27472 - ssdeep:
768:bgGzpD3p/UjijrgFREJsOdWI2VhGwtGyPaCpIt+o7jk+02XRmg:kGFTp7YVMAGyPaCyt+sw92XRmg - TLSH:
T1122F6CF75097EC4DBA879B43ACAB115A9089C78C6132E7A1488C377CE47C5BDAE10871 - Submitted as: 6363393.pdf
- File type: pdf · Size: 34714 bytes
- Verdict: malicious (71/100)
Detections (2 of 50 engines)
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/vopisovaz.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=don%20quijote%20dela%20mancha%20vicens%20vives, https://cdn.shopify.com/s/files/1/0501/8786/2194/files/maharashtra_district_wise_map.pdf, https://cdn.shopify.com/s/files/1/0484/0878/9150/files/83155320644.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=don%20quijote%20dela%20mancha%20vicens%20vives
- https://cdn.shopify.com/s/files/1/0501/8786/2194/files/maharashtra_district_wise_map.pdf
- https://cdn.shopify.com/s/files/1/0484/0878/9150/files/83155320644.pdf
- https://cdn.shopify.com/s/files/1/0498/6162/3963/files/12329484273.pdf
- https://cdn.shopify.com/s/files/1/0497/5381/7252/files/70225409386.pdf
- https://cdn.shopify.com/s/files/1/0483/9735/3109/files/showbox_latest_update_apk_download.pdf
- https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/vopisovaz.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f8712298f6d9.pdf
- https://cdn-cms.f-static.net/uploads/4366004/normal_5f871de85a6bf.pdf
- https://uploads.strikinglycdn.com/files/9904ca1e-f0ea-4d4e-9234-c4e63667015d/sujek.pdf
- https://uploads.strikinglycdn.com/files/a42a0424-d7c8-48a1-b8dc-8fbf9c994fe8/2262219263.pdf
- https://uploads.strikinglycdn.com/files/ac91f9e8-cc1e-4bfd-8186-bc43eac2cb6e/tewebiwisexi.pdf
- https://site-1042511.mozfiles.com/files/1042511/39204692976.pdf
- https://site-1039783.mozfiles.com/files/1039783/pukusavana.pdf
- https://site-1042843.mozfiles.com/files/1042843/32664801875.pdf
- https://site-1040297.mozfiles.com/files/1040297/22967689328.pdf
- https://site-1048288.mozfiles.com/files/1048288/95204085383.pdf
- https://cdn.shopify.com/s/files/1/0427/4061/3286/files/bopitibagejed.pdf
- https://cdn.shopify.com/s/files/1/0494/2508/8679/files/talavo.pdf
- https://cdn.shopify.com/s/files/1/0434/0501/7249/files/bully_scholarship_apk_mod.pdf
- https://cdn.shopify.com/s/files/1/0499/3122/3202/files/intermediate_algebra_math_for_college_readiness_answers.pdf
- https://cdn.shopify.com/s/files/1/0436/1617/4237/files/endless_war_defense_hacked.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- nudojafobedem.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1042511.mozfiles.com
- site-1039783.mozfiles.com
- site-1042843.mozfiles.com
- site-1040297.mozfiles.com
- site-1048288.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report