MALICIOUS — c540b2152c6.pdf
MALICIOUS — c540b2152c6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (74/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b7ed3e5a009f23aaf3e015e505911645d506b2708521d491fc5ca1bc3e1f0fc0 - SHA-1:
9794e886c3fe1417626b8c1150d38d4ea3fdf4fb - MD5:
e91f575b8735dca3f917b4eda91828fb - ssdeep:
768:cgGzpDIpbMQd7v9ZzAcwPz3xoHTlK5biy/IlY7aRu+IcGaNzTxo:5GFkp8oHJSbiy/Il1ccGaNBo - TLSH:
T1F52F7DF35067ED4D7AC7AB83BDA7119A648AD3896133D7A044882B2CC47C6BD7F10960 - Submitted as: c540b2152c6.pdf
- File type: pdf · Size: 35091 bytes
- Verdict: malicious (74/100)
Detections (2 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 74/100 is the fusion of 4 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/f5cb2338-2827-4a25-80b6-1d673ed903ed/pakiladutuxedugoxavadege.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=libro%20de%20historia%20de%20tercero%20de%20secundaria, https://uploads.strikinglycdn.com/files/f5cb2338-2827-4a25-80b6-1d673ed903ed/pakiladutuxedugoxavadege.pdf, https://uploads.strikinglycdn.com/files/e8234e82-d3df-46e4-bf20-6bc3d3b1a077/jarezinaruluvunonalekure.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=libro%20de%20historia%20de%20tercero%20de%20secundaria
- https://uploads.strikinglycdn.com/files/f5cb2338-2827-4a25-80b6-1d673ed903ed/pakiladutuxedugoxavadege.pdf
- https://uploads.strikinglycdn.com/files/e8234e82-d3df-46e4-bf20-6bc3d3b1a077/jarezinaruluvunonalekure.pdf
- https://uploads.strikinglycdn.com/files/24411646-be82-4ba3-a3a6-f2af1d404870/24638458611.pdf
- https://cdn-cms.f-static.net/uploads/4373998/normal_5f8a2f3f93bf0.pdf
- https://cdn-cms.f-static.net/uploads/4366646/normal_5f8803b387f2a.pdf
- https://cdn-cms.f-static.net/uploads/4366389/normal_5f892466bbe77.pdf
- https://cdn-cms.f-static.net/uploads/4366057/normal_5f8748e4cec80.pdf
- https://cdn.shopify.com/s/files/1/0497/1518/3777/files/android_pie_multitasking_apk.pdf
- https://cdn.shopify.com/s/files/1/0432/8846/1478/files/vinajepedefixazakemerofaz.pdf
- https://tabuxeniki.weebly.com/uploads/1/3/2/6/132682737/dofuwikajabuj.pdf
- https://dojudiwoju.weebly.com/uploads/1/3/1/4/131406456/26bc8a275.pdf
- https://texitanoz.weebly.com/uploads/1/3/0/7/130739996/7228805.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/vutoz.pdf
- https://cdn.shopify.com/s/files/1/0431/3504/1702/files/jopapug.pdf
- https://cdn.shopify.com/s/files/1/0484/2759/7981/files/arctic_air_freezer_awf25_manual.pdf
- https://cdn.shopify.com/s/files/1/0430/9952/1178/files/14183298646.pdf
- https://cdn.shopify.com/s/files/1/0503/7060/9312/files/nizanarirode.pdf
- https://cdn.shopify.com/s/files/1/0498/5526/6978/files/crunchball_3000_unblocked.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- tabuxeniki.weebly.com
- dojudiwoju.weebly.com
- texitanoz.weebly.com
- boguvetasitob.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report