MALICIOUS — 3ee3d4d442.pdf
MALICIOUS — 3ee3d4d442.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
70131a810e7f4b4da5c10b7dd9e5f0437811c3ae0e9f384665fa5213375f71d0 - SHA-1:
e63a85369741c26428fb06db347f4b9b1ae2328b - MD5:
66605e0dbe277ebbf5686b68a72587f8 - ssdeep:
1536:5GFFpkwE0LDljZ98JEhdHxm5LgtMwal9FoPxQVVjY5U/teVMVNh6bxkDGTY7jWXZ:MFFpI6RjZ9XfH05oy9FICVjYPVM+Uv7E - TLSH:
T1523AE1F35197EC5CB986DB1368FA1164619AC7CE1023DBA06488363CC5BC7BDBE21A11 - Submitted as: 3ee3d4d442.pdf
- File type: pdf · Size: 96928 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/ae959.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=1991%20ford%20ranger%205%20speed%20manual%20transmission, https://site-1039198.mozfiles.com/files/1039198/43571245300.pdf, https://site-1048184.mozfiles.com/files/1048184/98447057685.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=1991%20ford%20ranger%205%20speed%20manual%20transmission
- https://site-1039198.mozfiles.com/files/1039198/43571245300.pdf
- https://site-1048184.mozfiles.com/files/1048184/98447057685.pdf
- https://site-1040528.mozfiles.com/files/1040528/fizotumuriwulu.pdf
- https://site-1039924.mozfiles.com/files/1039924/tugojepuwiz.pdf
- https://uploads.strikinglycdn.com/files/ca6ba121-7c6e-4ee2-b700-23a410015f97/rowaruxofifuxoj.pdf
- https://uploads.strikinglycdn.com/files/d7db6f8c-e099-4bd7-a909-f725ac6a12ce/lukafut.pdf
- https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/ae959.pdf
- https://kelobutino.weebly.com/uploads/1/3/0/9/130969458/ginanopozazuvoxi.pdf
- https://vurofagulomefu.weebly.com/uploads/1/3/1/4/131452840/2592974.pdf
- https://vozutadisifik.weebly.com/uploads/1/3/1/4/131483249/250429.pdf
- https://cdn-cms.f-static.net/uploads/4366964/normal_5f873681c5ce7.pdf
- https://cdn-cms.f-static.net/uploads/4366324/normal_5f8771d8d8dc1.pdf
- https://uploads.strikinglycdn.com/files/4b03afcc-65b8-4987-85f8-2e0faa56c434/69537685986.pdf
- https://uploads.strikinglycdn.com/files/032eff95-5f4b-4df2-aa7e-cf5b0e44111f/raxuziwawejigipaputasos.pdf
- https://uploads.strikinglycdn.com/files/a512a434-5022-46f5-8f32-b87c1f159d09/76364065842.pdf
- https://uploads.strikinglycdn.com/files/9d23ebc1-7aef-44d6-90d0-cc5ffb87448f/37478928633.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1039198.mozfiles.com
- site-1048184.mozfiles.com
- site-1040528.mozfiles.com
- site-1039924.mozfiles.com
- uploads.strikinglycdn.com
- nudojafobedem.weebly.com
- kelobutino.weebly.com
- vurofagulomefu.weebly.com
- vozutadisifik.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report