MALICIOUS — f61c52d047.pdf
MALICIOUS — f61c52d047.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
935b7cf1a37d79ddeea543ca54c01b070eaef88c8aa5e76d6728c4503e8e9e92 - SHA-1:
cc13ac6fa91e12b834a418baea13a36e04681a51 - MD5:
22e330c045f852c915081835d3ebdc03 - ssdeep:
1536:iGFgpzSfuIZOAnGB3896u/ZyGdW0GUaC5/8SSdU6HyzWtlNE/NOA:bFgpziJOAnSA6TCaC5/8SS66SOg/3 - TLSH:
T1F038C0F311A7DD8C6AC7A7837EB62158904A938C7076AA6484C8763DC1FC2BDBF11910 - Submitted as: f61c52d047.pdf
- File type: pdf · Size: 79573 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://wonigebegi.weebly.com/uploads/1/3/1/6/131606731/turexir.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=ejercicios%20de%20distribucion%20de%20poisson%20y%20binomial, https://site-1044024.mozfiles.com/files/1044024/zafenegunidoperosakejuged.pdf, https://site-1038526.mozfiles.com/files/1038526/86973071535.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=ejercicios%20de%20distribucion%20de%20poisson%20y%20binomial
- https://site-1044024.mozfiles.com/files/1044024/zafenegunidoperosakejuged.pdf
- https://site-1038526.mozfiles.com/files/1038526/86973071535.pdf
- https://site-1036633.mozfiles.com/files/1036633/kewoxidemebusif.pdf
- https://wonigebegi.weebly.com/uploads/1/3/1/6/131606731/turexir.pdf
- https://pebiname.weebly.com/uploads/1/3/1/4/131453048/7b324388837a.pdf
- https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/kozasoj-gapuro-zuwidaru.pdf
- https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/luxuzolajewebe.pdf
- https://riwisasivituw.weebly.com/uploads/1/3/1/0/131070703/d33a4a57.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/164082fef46.pdf
- https://rivisoni.weebly.com/uploads/1/3/0/7/130739016/xiped_tiparelazelu_bofugefunu.pdf
- https://uploads.strikinglycdn.com/files/d4d65c93-849b-4f8b-85f6-c38d68cbf69a/64197911556.pdf
- https://uploads.strikinglycdn.com/files/462764d1-5216-4608-b337-db39960462b5/99128615014.pdf
- https://uploads.strikinglycdn.com/files/2c938735-2a1a-4404-8401-ec019affd263/84810679905.pdf
- https://uploads.strikinglycdn.com/files/99a5142b-1bdc-4358-99fa-091494b86f75/noduriminebezigil.pdf
- https://uploads.strikinglycdn.com/files/db2cdd21-6ed9-4227-9ae3-7f1dd685fc3a/79401163592.pdf
- https://uploads.strikinglycdn.com/files/a6874edd-46d7-4bef-96c1-e2b20dca0063/13660434345.pdf
- https://site-1048452.mozfiles.com/files/1048452/jakegulijiwaxinegu.pdf
- https://site-1039689.mozfiles.com/files/1039689/85795643301.pdf
- https://site-1037897.mozfiles.com/files/1037897/30560406310.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- c.pl
- site-1044024.mozfiles.com
- site-1038526.mozfiles.com
- site-1036633.mozfiles.com
- wonigebegi.weebly.com
- pebiname.weebly.com
- megadezatesaram.weebly.com
- sesuwulot.weebly.com
- riwisasivituw.weebly.com
- boguvetasitob.weebly.com
- rivisoni.weebly.com
- uploads.strikinglycdn.com
- site-1048452.mozfiles.com
- site-1039689.mozfiles.com
- site-1037897.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report