MALICIOUS — ba23efab5384c8.pdf
MALICIOUS — ba23efab5384c8.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 4 of 50 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
9667587c6ac58b65dbfed4cfbc2b5eb2a17812332aa43d56035e8421d1edce67 - SHA-1:
58a6feac4fd7c645bcfa9c6daa19a24243625830 - MD5:
a1b21383841e813aea1d8570751b6347 - ssdeep:
768:zgGzpDvdYi1sVuku26Fi0stdutEmoEvsJvOMYj3V1dVQyBmq4/:MGFjUhmoEvQvfW3VvBmq4/ - TLSH:
T173317CF7905BDD8C7A8A9F03AEEA15A86545C78D7137A76054C9333CC8B82FD2E50821 - Submitted as: ba23efab5384c8.pdf
- File type: pdf · Size: 40782 bytes
- Verdict: malicious (75/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 7 weighted signals:
- Contacted 15 external host(s) at runtime (4 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/6b320e0c-6e97-4134-bbc4-471abe031614/5e_monster_manual_download.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=schoolboy%20q%20crash%20talk%20merch, https://cdn-cms.f-static.net/uploads/4368228/normal_5f89bf9ff2d3e.pdf, https://cdn-cms.f-static.net/uploads/4368486/normal_5f95c3071e946.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (16 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=schoolboy%20q%20crash%20talk%20merch
- https://cdn-cms.f-static.net/uploads/4368228/normal_5f89bf9ff2d3e.pdf
- https://cdn-cms.f-static.net/uploads/4368486/normal_5f95c3071e946.pdf
- https://uploads.strikinglycdn.com/files/6b320e0c-6e97-4134-bbc4-471abe031614/5e_monster_manual_download.pdf
- https://uploads.strikinglycdn.com/files/57ca848f-ab49-4062-b73a-081eb3c1d395/musica_cristiana_adventista_en_espanol.pdf
- https://cdn.shopify.com/s/files/1/0482/4268/8154/files/12013054808.pdf
- https://cdn-cms.f-static.net/uploads/4367656/normal_5f91ad9091fea.pdf
- https://cdn-cms.f-static.net/uploads/4379387/normal_5f9b823a71520.pdf
- https://cdn.shopify.com/s/files/1/0502/0162/4727/files/konixuz.pdf
- https://cdn-cms.f-static.net/uploads/4387932/normal_5f925acc97a97.pdf
- https://cdn-cms.f-static.net/uploads/4368488/normal_5f8fe0f0a34a1.pdf
- https://cdn-cms.f-static.net/uploads/4402737/normal_5f946634336e0.pdf
- https://cdn-cms.f-static.net/uploads/4371020/normal_5f97fea7b707c.pdf
- https://cdn-cms.f-static.net/uploads/4380392/normal_5f9a2a385a312.pdf
- https://uploads.strikinglycdn.com/files/cc40bde4-53bd-4a0d-903a-d9507edac7b2/reflexion_el_sabio_y_el_viajero.pdf
- https://uploads.strikinglycdn.com/files/57ccd50d-37e7-4ced-a85e-adee03c39384/93921667096.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report