SUSPICIOUS — ecea2be33.pdf
SUSPICIOUS — ecea2be33.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
19dbb2fd66001298d61684eb7ce958a401c7df60d0617c9fd5a114bed881aa7c - SHA-1:
6565e3a7160bb3d35af5a4bfd7b0a2d885ff3aed - MD5:
adc749e055110cbd41624ba4b777bf58 - ssdeep:
768:ugGzpD9pTbtlk8JJaDy7uZinKsLhHCXzqjSQY2XdMu+UYmoFTGzd2KpqTYX:LGFRphWSuZmKsLhO+un2thKmiS2KpqEX - TLSH:
T146319DF350D7EC4DBA8AEB13AEA7109A5049D74C6136D7A0449C7B3DC4BC6BC6E60860 - Submitted as: ecea2be33.pdf
- File type: pdf · Size: 42983 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/b961a21c-8bde-4b9b-968c-0b9ad3f7a8cf/58382748650.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=go%20math%20assessment%20guide%20grade%205%20answer%20key, https://cdn.shopify.com/s/files/1/0432/6529/4504/files/mamma_mia_chiquitita.pdf, https://cdn.shopify.com/s/files/1/0434/7186/3961/files/stick_war_2_hacked_unblocked_games.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=go%20math%20assessment%20guide%20grade%205%20answer%20key
- https://cdn.shopify.com/s/files/1/0432/6529/4504/files/mamma_mia_chiquitita.pdf
- https://cdn.shopify.com/s/files/1/0434/7186/3961/files/stick_war_2_hacked_unblocked_games.pdf
- https://cdn.shopify.com/s/files/1/0432/1342/2753/files/aeneid_full_text_latin.pdf
- https://uploads.strikinglycdn.com/files/b961a21c-8bde-4b9b-968c-0b9ad3f7a8cf/58382748650.pdf
- https://uploads.strikinglycdn.com/files/7a010fb3-a11f-4a84-baae-2cd58e8e1316/remenerekixive.pdf
- https://uploads.strikinglycdn.com/files/d9742c9e-7ddb-429c-8380-081aedc76d19/saxumudokebirezo.pdf
- https://uploads.strikinglycdn.com/files/53a97000-7429-432b-a1ba-c724607d8a7d/vajudizuloxisamijixoro.pdf
- https://uploads.strikinglycdn.com/files/a02b0ec9-1b55-44a3-9677-851e2c11ecb5/97517394307.pdf
- https://site-1039295.mozfiles.com/files/1039295/toresapodasaz.pdf
- https://site-1043093.mozfiles.com/files/1043093/katilogavanedu.pdf
- https://site-1038738.mozfiles.com/files/1038738/28125194420.pdf
- https://site-1038581.mozfiles.com/files/1038581/23794503114.pdf
- https://cdn-cms.f-static.net/uploads/4365547/normal_5f870acc9dbb9.pdf
- https://cdn-cms.f-static.net/uploads/4366044/normal_5f87129f5e366.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/be47935eb28.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/8a68c5dc19.pdf
- https://lixaworone.weebly.com/uploads/1/3/1/8/131871871/2887594.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/8536469.pdf
- https://uploads.strikinglycdn.com/files/42b66d5c-2fd0-4434-a029-6908651dae95/39344600617.pdf
- https://uploads.strikinglycdn.com/files/517e7d2e-1cf8-4767-bcf5-097b62d2c83e/71811951231.pdf
- https://uploads.strikinglycdn.com/files/63ff417f-0020-4a38-b773-008053a9015e/67733570581.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1039295.mozfiles.com
- site-1043093.mozfiles.com
- site-1038738.mozfiles.com
- site-1038581.mozfiles.com
- cdn-cms.f-static.net
- vozunutav.weebly.com
- boguvetasitob.weebly.com
- lixaworone.weebly.com
- jakedekokobara.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report