MALICIOUS — digefig.pdf
MALICIOUS — digefig.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e8403e51def511a8f3d6d12aaf7eaf494d5e0d2bd7fac054ca913d4d07d809b9 - SHA-1:
74716c9bd07efd77ed5524d5f9750dec0de8ff0c - MD5:
09b8cab6b2965c0415bcab3ea1f5b03b - ssdeep:
768:ugGzpDMecl8lwUxP8m/Xn0EuzLLrtMSqez25Z9mAGAz3sdBpmODAyM7BJ:LGFIejX0Eu/2mAGisd6ODK7BJ - TLSH:
T19E33AFF30057ED8CBBC79B03ADE72159618AC74CA136A7A041983B2DC4BC67C7E14961 - Submitted as: digefig.pdf
- File type: pdf · Size: 49214 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/2c21e350ba.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=bright%20line%20eating%20maintenance%20food%20plan, https://site-1036936.mozfiles.com/files/1036936/68101305289.pdf, https://site-1038629.mozfiles.com/files/1038629/wejofajidura.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=bright%20line%20eating%20maintenance%20food%20plan
- https://site-1036936.mozfiles.com/files/1036936/68101305289.pdf
- https://site-1038629.mozfiles.com/files/1038629/wejofajidura.pdf
- https://site-1039950.mozfiles.com/files/1039950/wegizekuxugoki.pdf
- https://site-1040683.mozfiles.com/files/1040683/11521460763.pdf
- https://cdn.shopify.com/s/files/1/0497/2363/7917/files/38040140513.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/2c21e350ba.pdf
- https://taxajadotediru.weebly.com/uploads/1/3/0/8/130873824/124b884337150.pdf
- https://sibakixode.weebly.com/uploads/1/3/2/8/132814768/puwep-jusulanafuro.pdf
- https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/sesapilegipe.pdf
- https://uploads.strikinglycdn.com/files/266b3256-98f7-4b07-a6f4-ce5b74692837/84524814456.pdf
- https://uploads.strikinglycdn.com/files/810079e1-f7a2-410f-aa52-8b6024d679cb/43988011511.pdf
- https://site-1037883.mozfiles.com/files/1037883/rujiji.pdf
- https://site-1043117.mozfiles.com/files/1043117/45990985537.pdf
- https://site-1043294.mozfiles.com/files/1043294/69100230040.pdf
- https://site-1039693.mozfiles.com/files/1039693/wogonifivasawi.pdf
- https://cdn.shopify.com/s/files/1/0482/0018/8061/files/86131828050.pdf
- https://cdn.shopify.com/s/files/1/0432/1342/2753/files/frases_de_dios_para_jovenes_enamorados.pdf
- https://cdn.shopify.com/s/files/1/0497/3779/3697/files/video_guide_guns_germs_and_steel_episode_2.pdf
- https://cdn.shopify.com/s/files/1/0484/5053/5578/files/13907396844.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- site-1036936.mozfiles.com
- site-1038629.mozfiles.com
- site-1039950.mozfiles.com
- site-1040683.mozfiles.com
- cdn.shopify.com
- jufaxexave.weebly.com
- taxajadotediru.weebly.com
- sibakixode.weebly.com
- sesuwulot.weebly.com
- uploads.strikinglycdn.com
- site-1037883.mozfiles.com
- site-1043117.mozfiles.com
- site-1043294.mozfiles.com
- site-1039693.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report