SUSPICIOUS — dd9033d67f05d8.pdf
SUSPICIOUS — dd9033d67f05d8.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
15568b3bc3a08a66de6600bcb1ca012170b17eb251d58548a9536be6447bd3ba - SHA-1:
5786ce64e7ff5da24bcf865e5bce7654292d7db2 - MD5:
fefa3becc532470d7d67551ce92c40c6 - ssdeep:
768:CgGzpDypDOmHciPo/MaAJcXJFwGlv6RNb3+83IVse6aIHcbid:fGFGpPPfkBvgNb3+t16aI8bid - TLSH:
T126329EF308A7EC8C7A8B6B536CB7169655C9D38C6137A7A00488376DD4BC5BE7E01860 - Submitted as: dd9033d67f05d8.pdf
- File type: pdf · Size: 45957 bytes
- Verdict: suspicious (58/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/33d6d83e-392c-4f3f-9414-d70754d2f8fc/kipokawabepelosada.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=beep%20codes%20troubleshooting%20pdf, https://uploads.strikinglycdn.com/files/33d6d83e-392c-4f3f-9414-d70754d2f8fc/kipokawabepelosada.pdf, https://uploads.strikinglycdn.com/files/c755c913-170d-4880-86e4-b9159239c132/ponoximulemojusiv.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=beep%20codes%20troubleshooting%20pdf
- https://uploads.strikinglycdn.com/files/33d6d83e-392c-4f3f-9414-d70754d2f8fc/kipokawabepelosada.pdf
- https://uploads.strikinglycdn.com/files/c755c913-170d-4880-86e4-b9159239c132/ponoximulemojusiv.pdf
- https://uploads.strikinglycdn.com/files/e77c1cef-554c-4ee4-acab-1c39501c3a3b/temasatuneliseruvimepizi.pdf
- https://uploads.strikinglycdn.com/files/16f80d8d-d162-4165-8cf4-149996a58cb7/mewevakorawibubabu.pdf
- https://uploads.strikinglycdn.com/files/23dbc91f-3f82-409f-80eb-c0ab8f501751/fujasufurivonimukosufuzum.pdf
- https://uploads.strikinglycdn.com/files/beb9d749-d7e9-4c10-ba6f-fc142643e1eb/nodoferorilonobofufuwas.pdf
- https://uploads.strikinglycdn.com/files/2d067083-117a-480b-a969-a9c7bd6e502b/jukerojilijumowumekikurog.pdf
- https://uploads.strikinglycdn.com/files/5b7d0ae2-3a13-41ca-bcea-2fba8ad0eeea/87120477259.pdf
- https://uploads.strikinglycdn.com/files/d6b8a9f1-0773-4e42-b7c9-bd9723a09f8b/25925898794.pdf
- https://uploads.strikinglycdn.com/files/241dccb6-13b7-4be8-b7dc-1502eac1a2a9/wamazis.pdf
- https://cdn-cms.f-static.net/uploads/4366063/normal_5f8768d8ab5b8.pdf
- https://cdn-cms.f-static.net/uploads/4366665/normal_5f87821fb04ad.pdf
- https://cdn-cms.f-static.net/uploads/4366965/normal_5f87525c2853e.pdf
- https://site-1038472.mozfiles.com/files/1038472/jogumasopozu.pdf
- https://site-1043458.mozfiles.com/files/1043458/21904902910.pdf
- https://site-1038958.mozfiles.com/files/1038958/pimunopopeko.pdf
- https://site-1039346.mozfiles.com/files/1039346/83125767186.pdf
- https://wefolukozik.weebly.com/uploads/1/3/1/4/131406413/98d92f61a605.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/1d1f8ecc085ca.pdf
- https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/luloxanibi.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/3029889.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/7775416.pdf
- https://ruwopevod.weebly.com/uploads/1/3/1/3/131397973/7833278.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/jinitorip-bolag.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1038472.mozfiles.com
- site-1043458.mozfiles.com
- site-1038958.mozfiles.com
- site-1039346.mozfiles.com
- wefolukozik.weebly.com
- mogilifus.weebly.com
- sesuwulot.weebly.com
- jakedekokobara.weebly.com
- ruwopevod.weebly.com
- gimejexoxixaza.weebly.com
- pumowurunumig.weebly.com
- wuvirinofibugiz.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report