MALICIOUS — 7035142.pdf
MALICIOUS — 7035142.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (77/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f37f1bd4f004efe0fecd9b2fa94fcf888ba5938ced230fbbae052904c6c47e57 - SHA-1:
2d7338ca6ab16bc88e7e5f4eceaf38e34ca5079b - MD5:
d9e1b92f20d6755f6ef87851761e7811 - ssdeep:
768:RgGzpDIpzNHixHkzS/zBqhRSYMe/lhIpavSKnOdqZH1xaEp9/+Y7kNzYxzD:iGFkpSHmS/jWthIpoShd+1cVzYxzD - TLSH:
T15E339EF340A3ED8C7A8A7B639D6B109DB19AC7CC2127D36414CC269D84787ED6F00A61 - Submitted as: 7035142.pdf
- File type: pdf · Size: 48386 bytes
- Verdict: malicious (77/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 77/100 is the fusion of 5 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded link rated suspicious by URL analysis: https://vatipasa.weebly.com/uploads/1/3/0/7/130775610/fa7400d3.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=baal%20veer%202%20episode%203%20video, https://uploads.strikinglycdn.com/files/c96fadb4-203a-4526-8d4e-80c3f99cf817/79452194157.pdf, https://uploads.strikinglycdn.com/files/14f309ba-6e67-4169-b5e7-73e1ba03c97e/xuxezefulekivofelakuwak.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=baal%20veer%202%20episode%203%20video
- https://uploads.strikinglycdn.com/files/c96fadb4-203a-4526-8d4e-80c3f99cf817/79452194157.pdf
- https://uploads.strikinglycdn.com/files/14f309ba-6e67-4169-b5e7-73e1ba03c97e/xuxezefulekivofelakuwak.pdf
- https://uploads.strikinglycdn.com/files/f3a75b81-cf3e-4b20-a37f-9ab036479f3d/mokekebifudiwetibazut.pdf
- https://uploads.strikinglycdn.com/files/b8c71376-1802-431a-ae5b-d22c5f10e7bb/559346197.pdf
- https://uploads.strikinglycdn.com/files/1dba0e5a-da9d-4348-8bb1-9734724aed02/59975549077.pdf
- https://vatipasa.weebly.com/uploads/1/3/0/7/130775610/fa7400d3.pdf
- https://towetebofipu.weebly.com/uploads/1/3/1/4/131437669/wubetigaxolak_dipasotesowuvu_fiwaparaveli_zexapeteguje.pdf
- https://uploads.strikinglycdn.com/files/853aefd7-dee1-4313-8f5d-24bd04377fab/raratajafimosakog.pdf
- https://uploads.strikinglycdn.com/files/4a9ee242-01df-4471-9a65-a8612a68ef1d/vonenurozobo.pdf
- https://uploads.strikinglycdn.com/files/3976e287-89be-4395-b1c7-41f75daaf94e/jinonasudumolipiga.pdf
- https://uploads.strikinglycdn.com/files/51d94588-355a-42a8-8b2d-48742467383e/65566732301.pdf
- https://uploads.strikinglycdn.com/files/972de9b5-1c8c-414a-a930-c09906fe54c8/rilisaxogovabuwipobij.pdf
- https://uploads.strikinglycdn.com/files/009cb140-c0ac-41b1-aac1-0b115a3848a5/75228451564.pdf
- https://uploads.strikinglycdn.com/files/958ad9cc-9458-46fe-baf0-0fecd897b98f/desafemuzusitaxesowim.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/ce02014a20d.pdf
- https://ponixojezunuto.weebly.com/uploads/1/3/0/9/130969897/ranijev.pdf
- https://rezizeme.weebly.com/uploads/1/3/0/7/130775554/aaa1b366bd7fe.pdf
- https://buxivadoga.weebly.com/uploads/1/3/0/7/130740323/jivon.pdf
- https://pumowurunumig.weebly.com/uploads/1/3/2/7/132740285/zamupudebomimaze.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- vatipasa.weebly.com
- towetebofipu.weebly.com
- bedizegoresupa.weebly.com
- ponixojezunuto.weebly.com
- rezizeme.weebly.com
- buxivadoga.weebly.com
- pumowurunumig.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report