SUSPICIOUS — ebc7f.pdf
SUSPICIOUS — ebc7f.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
007bb9911421bb361c3606a81b1953bc53ebbd639340d75c48841492adc9a668 - SHA-1:
bcfc6aeaa59d7b0613e08a7c846b2ced4dec39c4 - MD5:
09bb4b09978b833a3fd22114b16998a9 - ssdeep:
1536:mSGFcp6b0k7o0HhCnk6y41iDDN/58halupp:mLFcpDk7ZHW7xiDDNh8glK - TLSH:
T1EB34AFF710E7ED8D3E4B9B07ADAB0169B046C78D603687A005C86B2DC4BCABD3E14555 - Submitted as: ebc7f.pdf
- File type: pdf · Size: 53560 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://cdn-cms.f-static.net/uploads/4367000/normal_5f872ff2dbff4.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=ellen%20g%20white%20livros%20pdf, https://cdn-cms.f-static.net/uploads/4371787/normal_5f95fa6ec6e5a.pdf, https://cdn-cms.f-static.net/uploads/4367000/normal_5f8a40466b6bb.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=ellen%20g%20white%20livros%20pdf
- https://cdn-cms.f-static.net/uploads/4371787/normal_5f95fa6ec6e5a.pdf
- https://cdn-cms.f-static.net/uploads/4367000/normal_5f8a40466b6bb.pdf
- https://cdn-cms.f-static.net/uploads/4367000/normal_5f872ff2dbff4.pdf
- https://s3.amazonaws.com/jifesu/21041158262.pdf
- https://s3.amazonaws.com/bubodeliza/a_season_in_hell_arthur_rimbaud.pdf
- https://s3.amazonaws.com/lewuli/nilowuwobaniwusaxikuj.pdf
- https://uploads.strikinglycdn.com/files/b6e966e2-60db-4757-8f7c-27b42674bd6f/turirokivusudilakufiv.pdf
- https://uploads.strikinglycdn.com/files/b9bb7aa6-bc16-43e1-b5d8-a56c86df1384/17170917634.pdf
- https://uploads.strikinglycdn.com/files/3f4efc66-ff4b-4153-bcf7-cfbec65f4cc3/18272597509.pdf
- https://uploads.strikinglycdn.com/files/96cfacf6-0c86-4fa3-afeb-150f4510b9ae/liwitegiwunivorufezedum.pdf
- https://uploads.strikinglycdn.com/files/7d1fdb03-487d-45bc-85b7-384dd10c04f7/indian_express_telegram_channel.pdf
- https://uploads.strikinglycdn.com/files/98a65083-43e2-4a7d-bb70-50229c468837/tovezumim.pdf
- https://uploads.strikinglycdn.com/files/a9f0f1e7-43d2-4543-9f8d-eade7e8fd5dc/vodago.pdf
- https://uploads.strikinglycdn.com/files/31a69be9-ca95-4c4d-9659-97f799e4c837/80095475913.pdf
- https://uploads.strikinglycdn.com/files/555aee2c-035b-4ca2-bf3b-f92e54c4be43/pisusupiwomawapiwagira.pdf
- https://cdn-cms.f-static.net/uploads/4367308/normal_5f87e2c384aa5.pdf
- https://cdn-cms.f-static.net/uploads/4375203/normal_5f9006a59244d.pdf
- https://cdn-cms.f-static.net/uploads/4369182/normal_5f89e3556ddea.pdf
- https://uploads.strikinglycdn.com/files/4ad37b74-eba4-4a93-8336-fd1a061518c3/99883281598.pdf
- https://uploads.strikinglycdn.com/files/8bd0e2cd-7127-4d3a-a2a2-651b672e88a5/zumdahl_chemistry_8th_edition_fr.pdf
- https://uploads.strikinglycdn.com/files/206577b2-80e8-4e0e-b272-acf312e368d8/dadufenidopomev.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- s3.amazonaws.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report