MALICIOUS — 5186611.pdf
MALICIOUS — 5186611.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3d295a3cb35db0a0dc356993fd1e5d941d2ed0ff22957da3f643d35bdcda97a4 - SHA-1:
94007cb036902e36cb443d3fad1ceb8be41cc86f - MD5:
5fe026493a49c934c6156096b9729d44 - ssdeep:
768:ngGzpD9paONf+xc6I0Pm7NLz6CTLaddSnI6d8dqka8xnd+QLyrH64Tiax60W:gGFJpaSf4c6PCLTnCzyrH64x60W - TLSH:
T1E9348EF344A7ED8C7A4EAF03AEA61599604AD78C7022976044CC272CD5BC6FD6F10A61 - Submitted as: 5186611.pdf
- File type: pdf · Size: 55411 bytes
- Verdict: malicious (75/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/7879e5a.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=mcintosh%20mc%20240%20manual, https://jopulovi.weebly.com/uploads/1/3/4/2/134265775/1504306.pdf, https://lodirunesu.weebly.com/uploads/1/3/0/8/130874391/kagejosuwu-bufegolofajog-pujefadu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=mcintosh%20mc%20240%20manual
- https://jopulovi.weebly.com/uploads/1/3/4/2/134265775/1504306.pdf
- https://lodirunesu.weebly.com/uploads/1/3/0/8/130874391/kagejosuwu-bufegolofajog-pujefadu.pdf
- https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/7879e5a.pdf
- https://uploads.strikinglycdn.com/files/21c885a9-7717-4deb-97bd-b01a6934633d/vigofajino.pdf
- https://uploads.strikinglycdn.com/files/d5af6823-afa4-4829-9d7e-18e17ff5744e/kepuma.pdf
- https://uploads.strikinglycdn.com/files/7f81fc38-2e9f-44bb-94f5-ee32baf78897/mijiduzimatezuni.pdf
- https://uploads.strikinglycdn.com/files/bcfed20d-157f-48fa-8047-79292e10f3df/37760108457.pdf
- https://uploads.strikinglycdn.com/files/6217b645-7be1-4136-ba7b-a03e3a457514/lokeximilumepufifakejo.pdf
- https://uploads.strikinglycdn.com/files/b2ac7883-0767-4541-992e-7dc9094576b8/gozenufelogefazezixeletot.pdf
- https://cdn-cms.f-static.net/uploads/4375197/normal_5f8bed40b1b35.pdf
- https://cdn-cms.f-static.net/uploads/4368950/normal_5f88ad4878301.pdf
- https://cdn-cms.f-static.net/uploads/4367000/normal_5f873c95a4376.pdf
- https://cdn-cms.f-static.net/uploads/4383582/normal_5f9274249c04c.pdf
- https://cdn.shopify.com/s/files/1/0481/8914/5245/files/magifenizon.pdf
- https://cdn.shopify.com/s/files/1/0481/3560/2339/files/zimepebavati.pdf
- https://cdn.shopify.com/s/files/1/0431/5440/7578/files/68410494287.pdf
- https://cdn.shopify.com/s/files/1/0483/8182/1088/files/hard_reset_spice_android_one.pdf
- https://s3.amazonaws.com/wixamupelinere/87449012582.pdf
- https://s3.amazonaws.com/dejolavubukugeb/kevanupos.pdf
- https://s3.amazonaws.com/tadovu/jadomiriletesovixetor.pdf
- https://s3.amazonaws.com/vavale/zogiguvaw.pdf
- https://s3.amazonaws.com/tadovu/zugakoserazonukovimonupoj.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- jopulovi.weebly.com
- lodirunesu.weebly.com
- kabudededawizo.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report