MALICIOUS — 5464397.pdf
MALICIOUS — 5464397.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6ed62d1e7d3f8708d74da39751200535a37ca3e92545b4e455630b966903f5eb - SHA-1:
ffbb71808e55abcf0a70cc4f30ce6d835dd0aa2f - MD5:
5d24cc6c9827a9e33ba069cb7ed71423 - ssdeep:
768:PgGzpD0apIQ/dzm8oRTpYeeGFww3a+pjmWqooCYED82bjL+Sn8s/K:4GFrpIQ/Ke0wDUjs2I2nLJn8s/K - TLSH:
T103328DF70097DD8C364B6B13AEEB1469514AC38C6232DB9054887B7CD4BC6BCAD60A61 - Submitted as: 5464397.pdf
- File type: pdf · Size: 45528 bytes
- Verdict: malicious (75/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://juporolo.weebly.com/uploads/1/3/1/3/131380745/64574e707272.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=pc%20troubleshooting%20tutorial%20pdf, https://cdn.shopify.com/s/files/1/0432/8584/0036/files/babusafogupofuli.pdf, https://cdn.shopify.com/s/files/1/0501/6161/5003/files/jozazifevikizun.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=pc%20troubleshooting%20tutorial%20pdf
- https://cdn.shopify.com/s/files/1/0432/8584/0036/files/babusafogupofuli.pdf
- https://cdn.shopify.com/s/files/1/0438/1966/3522/files/research_proposal_questions_and_answers.pdf
- https://cdn.shopify.com/s/files/1/0501/6161/5003/files/jozazifevikizun.pdf
- https://cdn.shopify.com/s/files/1/0497/4500/2657/files/a_different_mirror_takaki.pdf
- https://cdn-cms.f-static.net/uploads/4372723/normal_5f8abc2439787.pdf
- https://s3.amazonaws.com/felasorarabipis/95799152124.pdf
- https://s3.amazonaws.com/henghuili-files2/tibudozenowevugevezelik.pdf
- https://s3.amazonaws.com/tetazino/65434491877.pdf
- https://s3.amazonaws.com/kavitokolezub/analog_and_digital_electronics_objective_questions_and_answers.pdf
- https://uploads.strikinglycdn.com/files/90bed750-861d-45cc-abbb-e3fd78752626/50427541307.pdf
- https://uploads.strikinglycdn.com/files/613b3f67-93c6-45fc-a216-1be4eac28a23/94954747203.pdf
- https://juporolo.weebly.com/uploads/1/3/1/3/131380745/64574e707272.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/ruxozukozuvazu.pdf
- https://mabanopovofed.weebly.com/uploads/1/3/1/4/131453130/1564085.pdf
- https://siregudak.weebly.com/uploads/1/3/0/7/130738759/vukavofoges-rigerodime-jadupozatifen.pdf
- https://uploads.strikinglycdn.com/files/3016c3bd-c273-49af-b8ff-906bd0e086aa/31289122072.pdf
- https://uploads.strikinglycdn.com/files/e0f2cd07-10ab-4e9c-ad7a-6d66736be4fc/78886130706.pdf
- https://uploads.strikinglycdn.com/files/59501206-5e1d-4458-b1b6-095fd319c812/regejujikugixupotuvixiz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- uploads.strikinglycdn.com
- juporolo.weebly.com
- jatorogerujew.weebly.com
- mabanopovofed.weebly.com
- siregudak.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report