MALICIOUS — ziban.pdf
MALICIOUS — ziban.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (70/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e2b978c82052d2b2fe9ab84edf0dbce6b1141adb6508473c5f8cdb5cefd60371 - SHA-1:
66169903b60dcc464f1a967acd76a608d3850308 - MD5:
ade9bea2b78a81c5ad9ea7e959e8e7cd - ssdeep:
768:0gGzpDipRXSblHQaDx38quaMo13KSTZgZkf2vhA2oXk0nrUY1S9eeRiHL:BGFmpAvXfYy3lp11eRiHL - TLSH:
T116308DF31093ED8DBB8BAF07AEAB01AA5449C38A503BD7A1548C772CD47C5BD6E50850 - Submitted as: ziban.pdf
- File type: pdf · Size: 39103 bytes
- Verdict: malicious (70/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The malicious score of 70/100 is the fusion of 4 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://cctraff.ru/wb?keyword=trigonometry%20worksheet%20t3%20calculating%20sides, https://cdn.shopify.com/s/files/1/0499/3626/9470/files/sparknotes_a_raisin_in_the_sun_act_2.pdf, https://cdn.shopify.com/s/files/1/0502/5801/8472/files/10204626473.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=trigonometry%20worksheet%20t3%20calculating%20sides
- https://cdn.shopify.com/s/files/1/0499/3626/9470/files/sparknotes_a_raisin_in_the_sun_act_2.pdf
- https://cdn.shopify.com/s/files/1/0502/5801/8472/files/10204626473.pdf
- https://cdn.shopify.com/s/files/1/0499/8312/7712/files/gurokiwurutavevuturi.pdf
- https://cdn.shopify.com/s/files/1/0439/4916/2654/files/kawifotaxedutokewopex.pdf
- https://cdn.shopify.com/s/files/1/0437/5468/4565/files/walmart_coupon_2020_in_store.pdf
- https://cdn-cms.f-static.net/uploads/4366381/normal_5f879c70489e6.pdf
- https://cdn-cms.f-static.net/uploads/4373508/normal_5f8a198554522.pdf
- https://cdn-cms.f-static.net/uploads/4369786/normal_5f88fa47cb6e9.pdf
- https://cdn-cms.f-static.net/uploads/4366399/normal_5f8763490667d.pdf
- https://cdn.shopify.com/s/files/1/0484/5810/4986/files/office_365_sharepoint_administration_guide.pdf
- https://cdn.shopify.com/s/files/1/0440/6755/3430/files/why_did_the_renaissance_began_in_italy_answer_key.pdf
- https://uploads.strikinglycdn.com/files/c07ef164-1bb6-49f8-bd71-b3a13fd80638/93655760234.pdf
- https://uploads.strikinglycdn.com/files/8ac33c66-9edf-44ae-8559-66dff965b44c/velofilodejajemafide.pdf
- https://uploads.strikinglycdn.com/files/2a9e069b-8ba9-41ce-8a2a-84e814b5c89e/lanowikenufufikojefekor.pdf
- https://cdn-cms.f-static.net/uploads/4370089/normal_5f8ab6ec0caa2.pdf
- https://cdn-cms.f-static.net/uploads/4371497/normal_5f8a89137c453.pdf
- https://cdn-cms.f-static.net/uploads/4366034/normal_5f89dd5e02c57.pdf
- https://cdn.shopify.com/s/files/1/0437/7405/0458/files/mupovajiminakekal.pdf
- https://cdn.shopify.com/s/files/1/0496/3562/3076/files/metal_slug_unblocked.pdf
- https://cdn.shopify.com/s/files/1/0466/5281/7573/files/formato_dc-3_stps.pdf
- https://cdn.shopify.com/s/files/1/0433/3695/8106/files/chapter_10_section_1_meiosis_study_guide_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0438/5911/6182/files/xelitorenasafonodetadiz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report