MALICIOUS — bfb328e3892053.pdf
MALICIOUS — bfb328e3892053.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
45ae1efc305ea8f3df1046af5e27806a144d4101761ab54b197020ed39c1ab11 - SHA-1:
8837358e94eeafbb75a363adaf849268e29056b6 - MD5:
72ec215dbd59fbc47161702f3b909a33 - ssdeep:
1536:HGF7eMqfq8M7ZaHf3TzXGIXyB7fw73k0z:mF7enDMef3TzXGIiBrw73H - TLSH:
T177338DF30097DD4C7E87EB93ACB7255A6089D3887236A790548C772CC4BC66EAF01561 - Submitted as: bfb328e3892053.pdf
- File type: pdf · Size: 51157 bytes
- Verdict: malicious (75/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/297c0.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=paranormal%20activity%20t%C3%BCrk%C3%A7e%20dublaj%20in, https://cdn.shopify.com/s/files/1/0500/2513/6278/files/science_experiment_write_up_template.pdf, https://cdn.shopify.com/s/files/1/0497/3491/0101/files/bicycle_road_signs_meanings.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=paranormal%20activity%20t%C3%BCrk%C3%A7e%20dublaj%20in
- https://cdn.shopify.com/s/files/1/0500/2513/6278/files/science_experiment_write_up_template.pdf
- https://cdn.shopify.com/s/files/1/0497/3491/0101/files/bicycle_road_signs_meanings.pdf
- https://cdn.shopify.com/s/files/1/0498/4366/7143/files/genitive_case_exercises_with_answers.pdf
- https://cdn.shopify.com/s/files/1/0428/5104/1447/files/vuwitokobowibepijopilugix.pdf
- https://cdn-cms.f-static.net/uploads/4368772/normal_5f87e8908362c.pdf
- https://cdn-cms.f-static.net/uploads/4366645/normal_5f88dae1cee34.pdf
- https://cdn.shopify.com/s/files/1/0482/8987/4088/files/macroeconomia_blanchard_riassunto.pdf
- https://cdn.shopify.com/s/files/1/0437/0654/8379/files/16685217865.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/297c0.pdf
- https://zoveponezewuda.weebly.com/uploads/1/3/0/7/130738822/zifitam.pdf
- https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/c6125786ce3e.pdf
- https://nafeziwubiwodi.weebly.com/uploads/1/3/1/3/131379183/dedatulepogid-wonexupesog-xabanararip.pdf
- https://baletepo.weebly.com/uploads/1/3/0/7/130776023/0ab5b650.pdf
- https://mamunazeve.weebly.com/uploads/1/3/0/8/130814121/xazubotedobarumuk.pdf
- https://vunixumo.weebly.com/uploads/1/3/1/4/131453253/8783645.pdf
- https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/zuvekazabuz-topofelo-gupolekodojavo-ponabiloxe.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/ea1eadc07ab.pdf
- https://uploads.strikinglycdn.com/files/4d30cda0-2ce6-48b3-8fc0-64a835a60a58/51469888226.pdf
- https://uploads.strikinglycdn.com/files/5a7aa2a1-94c6-45af-b932-b1066f403d60/5492425801.pdf
- https://uploads.strikinglycdn.com/files/8543611e-7f11-42ad-a0a3-964829c62773/gevedoj.pdf
- https://uploads.strikinglycdn.com/files/946659bf-6250-4bb9-b4cb-7ffd324bd95f/kimapopaf.pdf
- https://uploads.strikinglycdn.com/files/5c51ee40-52c0-49d3-a0a6-dcf6b0d23d5c/87554974827.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- guwomenod.weebly.com
- zoveponezewuda.weebly.com
- megadezatesaram.weebly.com
- nafeziwubiwodi.weebly.com
- baletepo.weebly.com
- mamunazeve.weebly.com
- vunixumo.weebly.com
- fodezamu.weebly.com
- xojerajap.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report