SUSPICIOUS — 8009155.pdf
SUSPICIOUS — 8009155.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1f76216c4fd81ac41831935e198f8bbbd0b50c2fddbd769a7376e60b3bf4a39d - SHA-1:
344ebda7f98889d8d16278480a01f0ee6065a11e - MD5:
79ccaa3a7a5fd14923d063c0bab3de80 - ssdeep:
1536:5GF1euqk8xrl63Ojy8f0vVcyMEsghPrKi:MF1euqk8xrw3OXf0vWNghPL - TLSH:
T135338DF310A7ED8C7BCB6B03ADEB1159654AD24C6136E79048987B6CC4BC6FD6E00A50 - Submitted as: 8009155.pdf
- File type: pdf · Size: 51720 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/02ef52e6-2f00-46a0-b70c-2f5de31d8cdd/jumamamitaralimo.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=play%202k%20from%20another%20account%20not%20download, https://site-1044297.mozfiles.com/files/1044297/64632454280.pdf, https://site-1042013.mozfiles.com/files/1042013/38355637036.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=play%202k%20from%20another%20account%20not%20download
- https://site-1044297.mozfiles.com/files/1044297/64632454280.pdf
- https://site-1042013.mozfiles.com/files/1042013/38355637036.pdf
- https://site-1042448.mozfiles.com/files/1042448/80624456938.pdf
- https://site-1042539.mozfiles.com/files/1042539/sugefog.pdf
- https://site-1036880.mozfiles.com/files/1036880/kezizogunow.pdf
- https://site-1039886.mozfiles.com/files/1039886/kidaxipelitugimim.pdf
- https://site-1048476.mozfiles.com/files/1048476/pejukemiwuta.pdf
- https://site-1043259.mozfiles.com/files/1043259/nujevadejebuwul.pdf
- https://uploads.strikinglycdn.com/files/02ef52e6-2f00-46a0-b70c-2f5de31d8cdd/jumamamitaralimo.pdf
- https://uploads.strikinglycdn.com/files/638dfa53-0dbc-4dc6-b735-85a217ea1341/kusumu.pdf
- https://texitanoz.weebly.com/uploads/1/3/0/7/130739996/wavumopeduwi-vivugopofujudoz-lixepufinuza.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/tixobenudofezibet.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/0cbd7f35736ab.pdf
- https://lodirunesu.weebly.com/uploads/1/3/0/8/130874391/9826c.pdf
- https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/kakogu_sifafuv_xawoputuf.pdf
- https://site-1042937.mozfiles.com/files/1042937/sepolorivibevi.pdf
- https://site-1040896.mozfiles.com/files/1040896/97436327584.pdf
- https://site-1041854.mozfiles.com/files/1041854/sajivupenerinabupesoxuw.pdf
- https://site-1036828.mozfiles.com/files/1036828/nuragovuxuva.pdf
- https://cdn.shopify.com/s/files/1/0481/3986/2183/files/38869639808.pdf
- https://cdn.shopify.com/s/files/1/0496/2667/7399/files/260_drum_machine_patterns_ableton_live.pdf
- https://cdn.shopify.com/s/files/1/0434/8713/3860/files/inova_fairfax_medical_campus_map.pdf
- https://cdn.shopify.com/s/files/1/0501/7233/0163/files/7044240865.pdf
- https://cdn.shopify.com/s/files/1/0431/7026/7291/files/trevor_noah_afraid_of_the_dark_review.pdf
Embedded domains
- cctraff.ru
- site-1044297.mozfiles.com
- site-1042013.mozfiles.com
- site-1042448.mozfiles.com
- site-1042539.mozfiles.com
- site-1036880.mozfiles.com
- site-1039886.mozfiles.com
- site-1048476.mozfiles.com
- site-1043259.mozfiles.com
- uploads.strikinglycdn.com
- texitanoz.weebly.com
- mogilifus.weebly.com
- jakedekokobara.weebly.com
- lodirunesu.weebly.com
- juragubiv.weebly.com
- site-1042937.mozfiles.com
- site-1040896.mozfiles.com
- site-1041854.mozfiles.com
- site-1036828.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report