MALICIOUS — f4c390bae4dab7.pdf
MALICIOUS — f4c390bae4dab7.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
65e68a898958fcbcf50eb7be630b67dc1a82aa7333739ad871a5ea42041ec42b - SHA-1:
135590ee368c28d6b23e29fc3f10d05e7eda2a84 - MD5:
40620504f322f8cc7ce6b8191d7ea964 - ssdeep:
768:8xgGzpDweDkEgEDycWo4PHBNqK75kTQt8DL/5RdMFTdj:bGFkeFb45NqEaL/5n2Tdj - TLSH:
T160316CF34067DD9C7ACBAB43AEFA205D604ADB4861329790449C676CC4BC2BD7F40A61 - Submitted as: f4c390bae4dab7.pdf
- File type: pdf · Size: 39472 bytes
- Verdict: malicious (71/100)
Detections (2 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/ratefunerod.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=madea%20family%20reunion%20play%20full%20movie, https://site-1039162.mozfiles.com/files/1039162/finuwotedadalusunupab.pdf, https://site-1039921.mozfiles.com/files/1039921/xixipurixemugajebonu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=madea%20family%20reunion%20play%20full%20movie
- https://site-1039162.mozfiles.com/files/1039162/finuwotedadalusunupab.pdf
- https://site-1039921.mozfiles.com/files/1039921/xixipurixemugajebonu.pdf
- https://site-1039487.mozfiles.com/files/1039487/fables_de_la_fontaine_livre_7.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/ratefunerod.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/09b03b.pdf
- https://buluzuzumaz.weebly.com/uploads/1/3/1/6/131636727/c372e.pdf
- https://fekudumubaf.weebly.com/uploads/1/3/2/6/132681201/kogog.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/xojajuv-mitegejitokuxig.pdf
- https://tenagudewujuga.weebly.com/uploads/1/3/1/1/131164273/xuxixeme_toxam_voxuxi_bawereg.pdf
- https://uploads.strikinglycdn.com/files/ce296611-0d8e-4550-a9e4-005959b870ea/27848881801.pdf
- https://uploads.strikinglycdn.com/files/30271c68-046f-4ba7-a390-8f68b0ae4015/pojekaminewefuvu.pdf
- https://uploads.strikinglycdn.com/files/febdba4d-bea7-4d68-8c5f-59e541d96644/1741258449.pdf
- https://uploads.strikinglycdn.com/files/71214af0-e5ea-4376-bfa2-90c0cb3f5046/dinudoduzuge.pdf
- https://uploads.strikinglycdn.com/files/9b99fc12-2048-4555-975e-a9611884d708/5611456791.pdf
- https://site-1036729.mozfiles.com/files/1036729/zofapib.pdf
- https://site-1043335.mozfiles.com/files/1043335/17888041279.pdf
- https://site-1036925.mozfiles.com/files/1036925/25624033435.pdf
- https://site-1040998.mozfiles.com/files/1040998/nomao_camera_android_free_download_apk.pdf
- https://site-1040358.mozfiles.com/files/1040358/41953088916.pdf
- https://site-1043532.mozfiles.com/files/1043532/90613284795.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- site-1039162.mozfiles.com
- site-1039921.mozfiles.com
- site-1039487.mozfiles.com
- dutitujazekap.weebly.com
- jatorogerujew.weebly.com
- buluzuzumaz.weebly.com
- fekudumubaf.weebly.com
- gimejexoxixaza.weebly.com
- tenagudewujuga.weebly.com
- uploads.strikinglycdn.com
- site-1036729.mozfiles.com
- site-1043335.mozfiles.com
- site-1036925.mozfiles.com
- site-1040998.mozfiles.com
- site-1040358.mozfiles.com
- site-1043532.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report