MALICIOUS — ab8c589.pdf
MALICIOUS — ab8c589.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d81afbeecabca0b2c63a146f9e220da17b3c64b32278cead4c5770b8e785a2db - SHA-1:
453fcbcc7c49dd448e0d606fba607b839eeb2d77 - MD5:
367b95be35630ba93e00f723d6282057 - ssdeep:
768:GgGzpDrpRQeksilfyOHG60sR0fe8e2gkXSBYdy1U2Jhbvre:TGF3p9am6Hn8e2bSBAkJdDe - TLSH:
T1D2327DF75093ED8C7ACFAB439EBB1258518AC78E7136D7905488672DC07C6AD3E04A60 - Submitted as: ab8c589.pdf
- File type: pdf · Size: 45325 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/sulusilalope-jobede.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=walmart%20retail%20link%20supplier%20login, https://uploads.strikinglycdn.com/files/d321c78d-37a0-4045-96f9-949663631127/22359078050.pdf, https://uploads.strikinglycdn.com/files/5ebde259-7fa5-4d02-b840-b65a21e08ee6/52266136138.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=walmart%20retail%20link%20supplier%20login
- https://uploads.strikinglycdn.com/files/d321c78d-37a0-4045-96f9-949663631127/22359078050.pdf
- https://uploads.strikinglycdn.com/files/5ebde259-7fa5-4d02-b840-b65a21e08ee6/52266136138.pdf
- https://uploads.strikinglycdn.com/files/fa320267-1744-4864-9ba9-71c4f3ace122/49827387129.pdf
- https://uploads.strikinglycdn.com/files/724a60fc-8f92-4c25-bf40-695d97f6d253/visimepenoxowin.pdf
- https://uploads.strikinglycdn.com/files/9b29f897-b3f4-47e2-85bf-1d6ed205eaa6/regabeduw.pdf
- https://uploads.strikinglycdn.com/files/37d11a68-4416-4a9a-9146-e4dd48a2378d/lolowufitoxem.pdf
- https://uploads.strikinglycdn.com/files/ad028cd8-daa2-472b-8031-81c39487d54a/91568171700.pdf
- https://uploads.strikinglycdn.com/files/98a6c045-4466-4e87-b317-b4a39c06678d/29876843835.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/sulusilalope-jobede.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/nidisetati.pdf
- https://sepikupi.weebly.com/uploads/1/3/0/7/130738949/kavawabukoweduz.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/0cbd7f35736ab.pdf
- https://uploads.strikinglycdn.com/files/48304c8e-6a33-48dc-b0ff-200f018ba6cc/42779867319.pdf
- https://uploads.strikinglycdn.com/files/6c335347-274e-4c03-837b-004fe337b67e/7820765933.pdf
- https://uploads.strikinglycdn.com/files/f3c5cbb2-8468-474b-84a3-7da5ffead246/wasowasuxotipix.pdf
- https://uploads.strikinglycdn.com/files/ee004227-f294-49f9-9eb2-57f32eda6fe1/57149059839.pdf
- https://site-1038460.mozfiles.com/files/1038460/tofulakunot.pdf
- https://site-1043081.mozfiles.com/files/1043081/90094862364.pdf
- https://site-1048574.mozfiles.com/files/1048574/wexakadi.pdf
- https://site-1040683.mozfiles.com/files/1040683/tapotejowobigubizezawal.pdf
- https://site-1040431.mozfiles.com/files/1040431/72899035562.pdf
- https://jukafubu.weebly.com/uploads/1/3/0/8/130874261/telopubujixamivope.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/bewomo.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/nitogewekarab.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- genigudepa.weebly.com
- dutitujazekap.weebly.com
- sepikupi.weebly.com
- jakedekokobara.weebly.com
- site-1038460.mozfiles.com
- site-1043081.mozfiles.com
- site-1048574.mozfiles.com
- site-1040683.mozfiles.com
- site-1040431.mozfiles.com
- jukafubu.weebly.com
- bedizegoresupa.weebly.com
- jufaxexave.weebly.com
- guwomenod.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report