SUSPICIOUS — a08c6c6b.pdf
SUSPICIOUS — a08c6c6b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
09cf92df3aacbff0a79323108b0298ee39cedc9d9c200aa8f7f559cd15e217bf - SHA-1:
9422c6f602f146cbb15870b2f4cb3f102c93578f - MD5:
045ee8b5d279ff5e45ca2ac522256510 - ssdeep:
3072:PFnpHRShJ/0O6o75mnw3A/YWqpXLy0UQ:NpHYv/Hh1iay8 - TLSH:
T1043BE1F31967EC4876CA9B13FEF92156504DE689A273CAE0C1882B3DD16C1BC7E40961 - Submitted as: a08c6c6b.pdf
- File type: pdf · Size: 106045 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/fd6b4f34-32a8-4899-8cd3-83971d158f17/fubuwibedijawiziwovu.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=manual%20de%20conceptos%20de%20formas%20arquitectonicas, https://uploads.strikinglycdn.com/files/fd6b4f34-32a8-4899-8cd3-83971d158f17/fubuwibedijawiziwovu.pdf, https://uploads.strikinglycdn.com/files/3186e44a-e5be-4f6a-86d3-e5e2574ad484/vedugumevez.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=manual%20de%20conceptos%20de%20formas%20arquitectonicas
- https://uploads.strikinglycdn.com/files/fd6b4f34-32a8-4899-8cd3-83971d158f17/fubuwibedijawiziwovu.pdf
- https://uploads.strikinglycdn.com/files/3186e44a-e5be-4f6a-86d3-e5e2574ad484/vedugumevez.pdf
- https://uploads.strikinglycdn.com/files/27932a58-91dc-4eb2-9728-a84b311ff6dd/kaviwisimovuwura.pdf
- https://uploads.strikinglycdn.com/files/4928653b-6304-4972-8af4-398279886fae/lezovikexuledezogulo.pdf
- https://site-1036698.mozfiles.com/files/1036698/7739620941.pdf
- https://site-1041684.mozfiles.com/files/1041684/36934716649.pdf
- https://site-1042677.mozfiles.com/files/1042677/stickman_rope_hero_mod_apk_unlimited_gems.pdf
- https://uploads.strikinglycdn.com/files/4cf01918-7591-4e6f-b1d9-3bb3e07d7812/82496429042.pdf
- https://uploads.strikinglycdn.com/files/fffcdecc-8952-45e6-88d1-b27771c8817d/lerifilologunabomarudo.pdf
- https://uploads.strikinglycdn.com/files/e393f2f9-1b08-4076-96c4-bdfa2c8680d7/zulozetogotosavurimop.pdf
- https://cdn.shopify.com/s/files/1/0484/2186/3582/files/59280273781.pdf
- https://cdn.shopify.com/s/files/1/0433/5520/9879/files/summertime_saga_flute_download.pdf
- https://cdn.shopify.com/s/files/1/0481/7738/1543/files/suxavojegupududivasawusu.pdf
- https://cdn.shopify.com/s/files/1/0266/9586/0417/files/myron_mixon_brisket_rubs.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f881b15ace87.pdf
- https://cdn-cms.f-static.net/uploads/4365591/normal_5f88eea4733da.pdf
- https://site-1037088.mozfiles.com/files/1037088/tapawabaforovuberifuro.pdf
- https://site-1038992.mozfiles.com/files/1038992/rodamaje.pdf
- https://site-1039992.mozfiles.com/files/1039992/kovugolero.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1036698.mozfiles.com
- site-1041684.mozfiles.com
- site-1042677.mozfiles.com
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1037088.mozfiles.com
- site-1038992.mozfiles.com
- site-1039992.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report