MALICIOUS — 1240140.pdf
MALICIOUS — 1240140.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
734b136f840545349943f0d26dd8ebde634c20c3aa9c068d2db8a4ef26702fff - SHA-1:
177ce9fa87091e2a9c56804ad1170112639ed474 - MD5:
e2ebf6e9ab4dc88e3da80f3ccca512a9 - ssdeep:
1536:HGFie3pBMwNdxqlREZkZycazeLhUKsyb:mFiev5nx24weeLhhs2 - TLSH:
T19236AEF750A7DD8C7B869B0369BB1096648ED7882232975044CCB76DC4BC6FEAF10960 - Submitted as: 1240140.pdf
- File type: pdf · Size: 64314 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/domovodibaposix.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=focuswriter%20themes%20download, https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/domovodibaposix.pdf, https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/e5bcd2697.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=focuswriter%20themes%20download
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/domovodibaposix.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/e5bcd2697.pdf
- https://dirigesibujov.weebly.com/uploads/1/3/0/9/130969991/43f9db53ee5.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/83905a54a030772.pdf
- https://wonigebegi.weebly.com/uploads/1/3/1/6/131606731/kolapabajiritu.pdf
- https://site-1041677.mozfiles.com/files/1041677/65989418322.pdf
- https://uploads.strikinglycdn.com/files/217381d7-9c85-42b3-a3bc-d76a7ca3bc90/jubitafomesuxuwemejuw.pdf
- https://uploads.strikinglycdn.com/files/b23643ee-28e8-45ad-8a6f-fa9dbb1ffc2e/tivilozukarokiloru.pdf
- https://uploads.strikinglycdn.com/files/1fb50ec5-31a4-49ba-a9b2-5736d319242d/notupuguwabox.pdf
- https://uploads.strikinglycdn.com/files/928ea29e-91d2-4131-95c9-466561bbe493/tadogexikasuxebonapejapop.pdf
- https://uploads.strikinglycdn.com/files/a5c097a3-a082-4292-96bd-8118e685d3f8/kugobavafuzajudexirul.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/pokobu-pidoror-pekirez.pdf
- https://medizagokitoni.weebly.com/uploads/1/3/2/3/132303310/gizixulu.pdf
- https://pobezewimo.weebly.com/uploads/1/3/2/6/132681951/duguweleda.pdf
- https://uploads.strikinglycdn.com/files/1c0a783f-9a8f-4a44-9b18-04bcdeedd77e/99977370262.pdf
- https://uploads.strikinglycdn.com/files/1fd40a1b-73c4-4c19-92bc-962b4c9326c2/51752112200.pdf
- https://uploads.strikinglycdn.com/files/1e64ec64-f168-491c-a065-e51bb3ca07c1/bixinidozupefeki.pdf
- https://uploads.strikinglycdn.com/files/2189fbf2-6f6b-4241-b95e-7bd72f870c60/65279969549.pdf
- https://uploads.strikinglycdn.com/files/5296f168-9119-4166-a70c-d1e934cc90c2/ruwoleligeralanojatu.pdf
- https://uploads.strikinglycdn.com/files/6cefe608-c0b0-4b31-a96a-6362d1167e77/63979458164.pdf
- https://uploads.strikinglycdn.com/files/af903caf-84ec-4160-9d09-23e2a7c04188/6364247855.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- guwomenod.weebly.com
- gimejexoxixaza.weebly.com
- dirigesibujov.weebly.com
- jakedekokobara.weebly.com
- wonigebegi.weebly.com
- site-1041677.mozfiles.com
- uploads.strikinglycdn.com
- zoxuzuxebexot.weebly.com
- medizagokitoni.weebly.com
- pobezewimo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report