MALICIOUS — 4184348.pdf
MALICIOUS — 4184348.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
487974bcc571ba21bc4e12675dbc8702d1bc3f2ef8f8e15208c468d589fc9f31 - SHA-1:
68302af745e5485c825d871760ea89824f2205d6 - MD5:
c21db7ca81a99cd481e6b00053038d34 - ssdeep:
768:QgGzpDkposLnkzJIgY0jA05WCSpOa1j4BkYwv4o+8bVJzoSH9SL:9GFgp5sJ9Jc0e9YM4o+iHX9SL - TLSH:
T1CA328DF310A7DE4C7E87AF536DAE296C6449D788622367A0409C672DC0BC27D7F50A60 - Submitted as: 4184348.pdf
- File type: pdf · Size: 45874 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/99ada916-f26b-46a6-a193-29b7b50ba641/fomuda.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=como%20hacer%20una%20tesis%20paso%20a%20paso, https://uploads.strikinglycdn.com/files/20e48943-807d-4baa-9c30-b506a90b02c3/tunerodebe.pdf, https://uploads.strikinglycdn.com/files/9694c27a-c092-4d20-8271-06d15704e983/48753990912.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=como%20hacer%20una%20tesis%20paso%20a%20paso
- https://uploads.strikinglycdn.com/files/20e48943-807d-4baa-9c30-b506a90b02c3/tunerodebe.pdf
- https://uploads.strikinglycdn.com/files/9694c27a-c092-4d20-8271-06d15704e983/48753990912.pdf
- https://uploads.strikinglycdn.com/files/a9bbdf87-b6ab-4020-ba59-39938ae4e43c/kolibobuginuxojonepebid.pdf
- https://uploads.strikinglycdn.com/files/6d011ef2-2b28-426d-9ef8-3a84894d5296/35594285434.pdf
- https://uploads.strikinglycdn.com/files/99ada916-f26b-46a6-a193-29b7b50ba641/fomuda.pdf
- https://cdn.shopify.com/s/files/1/0439/0351/6824/files/76001905557.pdf
- https://uploads.strikinglycdn.com/files/6d0925f2-8ab2-4348-9949-b89ad1bc9c2e/49971263587.pdf
- https://uploads.strikinglycdn.com/files/29023bc9-78f5-43e8-9dfa-546e9443e7f9/21100242812.pdf
- https://uploads.strikinglycdn.com/files/1693ba1b-061b-4ccb-be74-086d93bf6283/pafumikanujepepala.pdf
- https://uploads.strikinglycdn.com/files/1a25a63e-2f56-47ce-8054-fa6d5905de19/39913407966.pdf
- https://uploads.strikinglycdn.com/files/a18360cf-838b-494e-b532-f9b8a7196fc4/kixibamidotezepixet.pdf
- https://site-1044515.mozfiles.com/files/1044515/80314667696.pdf
- https://site-1043938.mozfiles.com/files/1043938/fibemajixibivizov.pdf
- https://uploads.strikinglycdn.com/files/8de4eb23-7d38-4938-9c0b-6400bbd2668d/84006999421.pdf
- https://uploads.strikinglycdn.com/files/8e6709ae-e0da-4e0e-adf0-7a9b87f3b7bb/felovosivutipixowumezeru.pdf
- https://uploads.strikinglycdn.com/files/a353fdd0-5535-44bf-807c-09644b88d889/pitomazejoderobisabekuso.pdf
- https://cdn-cms.f-static.net/uploads/4367927/normal_5f87cdc6c95dc.pdf
- https://cdn-cms.f-static.net/uploads/4366024/normal_5f878084b1fe2.pdf
- https://cdn-cms.f-static.net/uploads/4366032/normal_5f87be0c95faf.pdf
- https://cdn-cms.f-static.net/uploads/4368225/normal_5f87be93a7b55.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1044515.mozfiles.com
- site-1043938.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- u:\A
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report