MALICIOUS — 90b6836fdd98f6b.pdf
MALICIOUS — 90b6836fdd98f6b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8f49c145223fb847b3d8201ba0ff827f470ddf883baf8269d88721668c379ad8 - SHA-1:
fa896c698b643de147e4656e6578f7d04c23ea8b - MD5:
f7dc7c6b8af57725bb363944580e46dc - ssdeep:
3072:sFeVR6JfiO2dWjTkrT6OmV8BSw4LEvLIm:kGEf28n26/EB4LEvz - TLSH:
T12E3BE0F3911BDC8DBB8B9F83E89B21A5304AC7C86037975485C93AACC57C67C6E42910 - Submitted as: 90b6836fdd98f6b.pdf
- File type: pdf · Size: 102547 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/sulusilalope-jobede.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=%D9%85%D8%A4%D8%B3%D8%B3%D8%A9%20%D8%AA%D8%A3%D8%AC%D9%8A%D8%B1%20%D9%81%D9%88%D8%B1%D8%AA%20%D9%88%D9%8A%D9%86%20%D8%A5%D9%86%D8%AF%D9%8A%D8%A7%D9%86%D8%A7, https://cdn.shopify.com/s/files/1/0484/7127/7718/files/the_color_of_water_study_guide_packet_answer_key.pdf, https://cdn.shopify.com/s/files/1/0501/8481/4782/files/xodamekelixe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=%D9%85%D8%A4%D8%B3%D8%B3%D8%A9%20%D8%AA%D8%A3%D8%AC%D9%8A%D8%B1%20%D9%81%D9%88%D8%B1%D8%AA%20%D9%88%D9%8A%D9%86%20%D8%A5%D9%86%D8%AF%D9%8A%D8%A7%D9%86%D8%A7
- https://cdn.shopify.com/s/files/1/0484/7127/7718/files/the_color_of_water_study_guide_packet_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0501/8481/4782/files/xodamekelixe.pdf
- https://cdn.shopify.com/s/files/1/0485/0214/5185/files/what_can_ferrets_eat_and_not_eat.pdf
- https://cdn.shopify.com/s/files/1/0480/8245/2644/files/wolf_watch_season_3_episode_17.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/sulusilalope-jobede.pdf
- https://fewevivib.weebly.com/uploads/1/3/0/8/130813821/sopaxoduwojorojobu.pdf
- https://biwugina.weebly.com/uploads/1/3/1/1/131163984/wamix-nepoxek-besusaze.pdf
- https://site-1036744.mozfiles.com/files/1036744/31544691906.pdf
- https://site-1043175.mozfiles.com/files/1043175/xubabapatolemuve.pdf
- https://cdn-cms.f-static.net/uploads/4367301/normal_5f87b8d355e7e.pdf
- https://cdn-cms.f-static.net/uploads/4365575/normal_5f87000280a69.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/runemevurexuziwone.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/sidobojugonuxexoz.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/nesubine.pdf
- https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/vaxujow_gebonem.pdf
- https://wirukibit.weebly.com/uploads/1/3/0/9/130969322/2677845.pdf
- https://uploads.strikinglycdn.com/files/377a0d4f-44b4-4ae7-a5ed-79f48ef49cb4/tuduwovawo.pdf
- https://uploads.strikinglycdn.com/files/e4a2dadf-ef92-48d0-bcdb-50809aefc552/lewogali.pdf
- https://uploads.strikinglycdn.com/files/afdc2dbc-e7ef-42fb-b259-1b8684eea858/vibexo.pdf
- https://uploads.strikinglycdn.com/files/57c790b1-ebf1-486b-8aec-dda916b16d57/70728520159.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- genigudepa.weebly.com
- fewevivib.weebly.com
- biwugina.weebly.com
- site-1036744.mozfiles.com
- site-1043175.mozfiles.com
- cdn-cms.f-static.net
- dutitujazekap.weebly.com
- gimejexoxixaza.weebly.com
- nudojafobedem.weebly.com
- wirukibit.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report