MALICIOUS — d3322963e440a2a.pdf
MALICIOUS — d3322963e440a2a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8e43a63badd982f6bb86337155e2e0f12b054792bd265229b6759d22292291fc - SHA-1:
b2faac32b163f046faac798b783c5cc2c05330e6 - MD5:
e74b0f2ba16c62d263fbea5862780ee6 - ssdeep:
768:qgGzpDPpiu2UXaBDz4iMI+cLBEUcnvU4R9pcNqtm/A:3GFbpiuSCyCTU09QqtgA - TLSH:
T13A327DF340D7ED4C3A8B9F83ADA7269E9489D788613296610598B62CC47C7FD3F00951 - Submitted as: d3322963e440a2a.pdf
- File type: pdf · Size: 44189 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jonukejunuxesa.weebly.com/uploads/1/3/1/4/131409236/5854702.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=final%20ygs%20lys%20biyoloji%20konu%20anlat%C4%B1m%C4%B1%20pdf, https://jonukejunuxesa.weebly.com/uploads/1/3/1/4/131409236/5854702.pdf, https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/44d87feaf8ee.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=final%20ygs%20lys%20biyoloji%20konu%20anlat%C4%B1m%C4%B1%20pdf
- https://jonukejunuxesa.weebly.com/uploads/1/3/1/4/131409236/5854702.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/44d87feaf8ee.pdf
- https://nogafuku.weebly.com/uploads/1/3/2/8/132815296/5987814.pdf
- https://nikoxutaju.weebly.com/uploads/1/3/1/3/131378952/vomakobav_vamatapenavekik_mipukivof.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/jusokuzaleveg_daroditodore.pdf
- https://cdn.shopify.com/s/files/1/0427/8393/2582/files/lewes_de_headboat_fishing_report.pdf
- https://cdn.shopify.com/s/files/1/0433/2060/6885/files/14092204199.pdf
- https://cdn.shopify.com/s/files/1/0429/0609/1673/files/82081177219.pdf
- https://sepikupi.weebly.com/uploads/1/3/0/7/130738949/e375071c24.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/caa64.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/sefaritonos-nukivafeka-retisebop-regaxumex.pdf
- https://xumogimunosu.weebly.com/uploads/1/3/1/6/131607683/5157619.pdf
- https://xedaliwim.weebly.com/uploads/1/3/1/4/131454603/xisuvumuxefisa.pdf
- https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/texorabaseb.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/saxuvenimugugadeso.pdf
- https://fagisidide.weebly.com/uploads/1/3/2/6/132682833/newixexetukewobuse.pdf
- https://wuvirinofibugiz.weebly.com/uploads/1/3/1/0/131070402/df415b2.pdf
- https://kokubexajaluk.weebly.com/uploads/1/3/2/6/132681668/c726aa48700e.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f8924081aa48.pdf
- https://cdn-cms.f-static.net/uploads/4365570/normal_5f870213132bd.pdf
- https://cdn-cms.f-static.net/uploads/4366055/normal_5f872f157a487.pdf
- https://cdn-cms.f-static.net/uploads/4370263/normal_5f89043292497.pdf
- https://uploads.strikinglycdn.com/files/b43f0866-468b-436b-a89f-2baf2bc821cd/wirupurulobumepera.pdf
- https://uploads.strikinglycdn.com/files/7f3a01b1-2e0a-46c3-8af1-3c1cd8ae1d74/3672206970.pdf
Embedded domains
- cctraff.ru
- jonukejunuxesa.weebly.com
- mojivimimujovo.weebly.com
- nogafuku.weebly.com
- nikoxutaju.weebly.com
- xojerajap.weebly.com
- cdn.shopify.com
- sepikupi.weebly.com
- dimaxafazeza.weebly.com
- jawasolasazilem.weebly.com
- xumogimunosu.weebly.com
- xedaliwim.weebly.com
- tivakoxidedopa.weebly.com
- dutitujazekap.weebly.com
- fagisidide.weebly.com
- wuvirinofibugiz.weebly.com
- kokubexajaluk.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report