MALICIOUS — 0b9877ec.pdf
MALICIOUS — 0b9877ec.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b7a4d0eaadcf025f1fa6c86b43a213a766d71e392072d3d81a651cf991f8f1be - SHA-1:
d591e879379a34999dbf5824856fe1ad7c6498ed - MD5:
78f6fc2a9ea15657e5f4213c5f53c112 - ssdeep:
768:FgGzpDlp/qz3mLXztE4xPZXxqc054y/gXpwXJbs4VajY0fHjdELB3z053+bC0baL:WGF5pSz3mF0+ZXKZbXajY0fHjut303Mq - TLSH:
T16F326CF310A3DD4C7687EB03AEEE34695449E748A232E7604598676DC4BC77D7E40A20 - Submitted as: 0b9877ec.pdf
- File type: pdf · Size: 46634 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/gevoderovepiru.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=windows%20xp%20professional%20keygen, https://site-1043876.mozfiles.com/files/1043876/89007397120.pdf, https://site-1041074.mozfiles.com/files/1041074/53738186910.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=windows%20xp%20professional%20keygen
- https://site-1043876.mozfiles.com/files/1043876/89007397120.pdf
- https://site-1041074.mozfiles.com/files/1041074/53738186910.pdf
- https://site-1037022.mozfiles.com/files/1037022/30752443520.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/xewuj.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/8e42bfb8d1b0f.pdf
- https://bogadisosupotaj.weebly.com/uploads/1/3/0/7/130776541/sibaxat.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/gevoderovepiru.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/ronufebe-fazabewoxifuli-mitosi-sobonatifa.pdf
- https://site-1039002.mozfiles.com/files/1039002/76577147549.pdf
- https://site-1039642.mozfiles.com/files/1039642/guwibil.pdf
- https://site-1041950.mozfiles.com/files/1041950/53071941842.pdf
- https://site-1036995.mozfiles.com/files/1036995/61228297701.pdf
- https://site-1041081.mozfiles.com/files/1041081/77655611651.pdf
- https://cdn-cms.f-static.net/uploads/4365560/normal_5f87098cb5def.pdf
- https://cdn-cms.f-static.net/uploads/4366655/normal_5f874e951f5ad.pdf
- https://site-1037922.mozfiles.com/files/1037922/muzijitabewalelazut.pdf
- https://site-1038674.mozfiles.com/files/1038674/54397747585.pdf
- https://site-1039409.mozfiles.com/files/1039409/tabosedupabagofol.pdf
- https://site-1040298.mozfiles.com/files/1040298/67338433931.pdf
- https://cdn.shopify.com/s/files/1/0433/9236/8796/files/13783509435.pdf
- https://cdn.shopify.com/s/files/1/0484/5286/2113/files/partridge_in_a_pear_tree_picture.pdf
- https://cdn.shopify.com/s/files/1/0484/8972/6107/files/dr.fone_toolkit_for_android.pdf
- https://cdn.shopify.com/s/files/1/0495/6566/3384/files/28540903991.pdf
- https://cdn.shopify.com/s/files/1/0492/6826/1020/files/hyper_tough_tool_box_lock_replacement.pdf
Embedded domains
- cctraff.ru
- site-1043876.mozfiles.com
- site-1041074.mozfiles.com
- site-1037022.mozfiles.com
- bedizegoresupa.weebly.com
- bogadisosupotaj.weebly.com
- jawasolasazilem.weebly.com
- jufaxexave.weebly.com
- site-1039002.mozfiles.com
- site-1039642.mozfiles.com
- site-1041950.mozfiles.com
- site-1036995.mozfiles.com
- site-1041081.mozfiles.com
- cdn-cms.f-static.net
- site-1037922.mozfiles.com
- site-1038674.mozfiles.com
- site-1039409.mozfiles.com
- site-1040298.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report