MALICIOUS — nodap.pdf
MALICIOUS — nodap.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
51abc7dc7f202776ab77ca7cb7d86588a87d2d61177935b5f2cc084ae2116555 - SHA-1:
980f064241b306b4a51f82fc5ca8a12f78abafac - MD5:
09cb5eafc326735fee22e0d97a608e02 - ssdeep:
768:wgGzpDfpKkvU04KdaSTG4SV0yANPiG6RiBSM1mKvU2hk8pXBg5Mqd:dGFLpqESV7AgGRBd1mx2+IXBg5Mqd - TLSH:
T106329EF71093ED8C7B8E9B03AE6725EA158EC7886037D3A0459CA72CC4BC1BD6D11861 - Submitted as: nodap.pdf
- File type: pdf · Size: 46652 bytes
- Verdict: malicious (75/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/nupunitapubib.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=bandera%20y%20escudo%20de%20guayaquil, https://cdn-cms.f-static.net/uploads/4373516/normal_5f8a345dbc1f5.pdf, https://cdn-cms.f-static.net/uploads/4369318/normal_5f8bc7e824d64.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=bandera%20y%20escudo%20de%20guayaquil
- https://cdn-cms.f-static.net/uploads/4373516/normal_5f8a345dbc1f5.pdf
- https://cdn-cms.f-static.net/uploads/4369318/normal_5f8bc7e824d64.pdf
- https://cdn-cms.f-static.net/uploads/4383322/normal_5f8bb0282067a.pdf
- https://sokuvotaboraj.weebly.com/uploads/1/3/0/7/130776263/4823779.pdf
- https://ponixojezunuto.weebly.com/uploads/1/3/0/9/130969897/tudab-xulegig-palosupojufer.pdf
- https://vogizezadu.weebly.com/uploads/1/3/0/8/130814341/maxulegexe-liniriko-sovemogowi-raweluforibigog.pdf
- https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/nupunitapubib.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/3587330.pdf
- https://cdn.shopify.com/s/files/1/0432/7417/4622/files/amc_10_b_2020_solutions.pdf
- https://cdn.shopify.com/s/files/1/0435/0607/3759/files/93108224292.pdf
- https://cdn.shopify.com/s/files/1/0434/9893/0341/files/27057274943.pdf
- https://cdn.shopify.com/s/files/1/0496/2775/8763/files/90370372542.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/5473886.pdf
- https://virataxutepubom.weebly.com/uploads/1/3/0/8/130874282/kimodusanadumom.pdf
- https://buximinolid.weebly.com/uploads/1/3/1/3/131381316/xirusej_wejinelerukuxe_bizuxazixipa_tifukak.pdf
- https://riragojefo.weebly.com/uploads/1/3/1/8/131857115/bibumavimisa_lalile_zinifup.pdf
- https://xutewosabog.weebly.com/uploads/1/3/2/3/132303209/986987c496.pdf
- https://raxuzorufureraw.weebly.com/uploads/1/3/0/7/130775378/siruzewabami_refovafirux.pdf
- https://ditiwudo.weebly.com/uploads/1/3/1/4/131452947/6651589.pdf
- https://gemenudotipetal.weebly.com/uploads/1/3/2/6/132695720/mukerixeseze.pdf
- https://uploads.strikinglycdn.com/files/81a70c23-7565-44c3-8611-1e21e52babeb/leludoripepelojawilofobad.pdf
- https://uploads.strikinglycdn.com/files/f94995d1-f1c5-42d6-89f6-71b3eef09064/67847259281.pdf
- https://uploads.strikinglycdn.com/files/68b59e23-4eed-4379-893d-fddbd3a99a73/79524234154.pdf
- https://uploads.strikinglycdn.com/files/399bfd30-7153-4ed9-a7e6-6231c7d733b3/92616804804.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- sokuvotaboraj.weebly.com
- ponixojezunuto.weebly.com
- vogizezadu.weebly.com
- kabudededawizo.weebly.com
- tavumake.weebly.com
- cdn.shopify.com
- bedizegoresupa.weebly.com
- virataxutepubom.weebly.com
- buximinolid.weebly.com
- riragojefo.weebly.com
- xutewosabog.weebly.com
- raxuzorufureraw.weebly.com
- ditiwudo.weebly.com
- gemenudotipetal.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report