SUSPICIOUS — 1a17bbfb905.pdf
SUSPICIOUS — 1a17bbfb905.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
236cd65eeff4ca4414d4d13d1ce579614f72ff0f247cdb1c32eee5e699044c99 - SHA-1:
b1414262c6b64b6783b530a47c00a1368546c76a - MD5:
d2de994dbea8e693a0584e0f964df3a4 - ssdeep:
1536:DGFrpvS/AQfS+BlVvhqwWDiCqK0HZFJz0U:SFrpadlVvh7WDizFB - TLSH:
T108338DF350A7EC8D7A8E9F039DBB116D618AD7896132A760049C776CD0BC9ED7E00911 - Submitted as: 1a17bbfb905.pdf
- File type: pdf · Size: 49961 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://vimiwegom.weebly.com/uploads/1/3/0/7/130775837/pubufibezunekita.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=reconstructing%20gender%20a%20multicultura, https://uploads.strikinglycdn.com/files/f182c5fa-79a0-40e5-810a-cd5a801968db/gupamumiwutu.pdf, https://uploads.strikinglycdn.com/files/f7f8787f-2d3f-456c-be07-3cb05660ab7e/46368643601.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=reconstructing%20gender%20a%20multicultura
- https://uploads.strikinglycdn.com/files/f182c5fa-79a0-40e5-810a-cd5a801968db/gupamumiwutu.pdf
- https://uploads.strikinglycdn.com/files/f7f8787f-2d3f-456c-be07-3cb05660ab7e/46368643601.pdf
- https://uploads.strikinglycdn.com/files/51df00f9-0386-4a93-b055-335892dc7933/71789482668.pdf
- https://uploads.strikinglycdn.com/files/51e17001-c82b-43b4-9b49-3cc30dec6300/61158834433.pdf
- https://uploads.strikinglycdn.com/files/42e07844-f2f8-4ca6-8713-18b196fbbe2a/63929623176.pdf
- https://vimiwegom.weebly.com/uploads/1/3/0/7/130775837/pubufibezunekita.pdf
- https://jezaxegare.weebly.com/uploads/1/3/1/3/131380636/rogapojirilivoj.pdf
- https://wovasemuzusalej.weebly.com/uploads/1/3/1/6/131636629/0708510f.pdf
- https://ganulexotugoris.weebly.com/uploads/1/3/1/1/131164012/fonosapivomad_dexeverabibu_nevoviletapup_kefukexemuzor.pdf
- https://fizolapojola.weebly.com/uploads/1/3/1/3/131383549/3989030.pdf
- https://dujewukemapaf.weebly.com/uploads/1/3/1/4/131453220/konipojumujud.pdf
- https://ritibamubube.weebly.com/uploads/1/3/1/4/131437410/2508234.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/987b21c6b.pdf
- https://popilezofale.weebly.com/uploads/1/3/1/1/131164236/wogajag.pdf
- https://cdn.shopify.com/s/files/1/0464/8668/3800/files/36052352635.pdf
- https://cdn.shopify.com/s/files/1/0483/7651/2669/files/new_glenn_development_cost.pdf
- https://cdn.shopify.com/s/files/1/0496/5295/7335/files/ikea_malm_installation_guide.pdf
- https://cdn.shopify.com/s/files/1/0266/7967/3032/files/salisbury_beach_camping.pdf
- https://cdn.shopify.com/s/files/1/0494/7522/3719/files/62088277857.pdf
- https://site-1043090.mozfiles.com/files/1043090/60908879757.pdf
- https://site-1040136.mozfiles.com/files/1040136/lijawew.pdf
- https://site-1043844.mozfiles.com/files/1043844/wukoriwiwagazumu.pdf
- https://cdn.shopify.com/s/files/1/0434/3336/1574/files/xojewunigowanok.pdf
- https://cdn.shopify.com/s/files/1/0431/2639/0946/files/fizenadifu.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- vimiwegom.weebly.com
- jezaxegare.weebly.com
- wovasemuzusalej.weebly.com
- ganulexotugoris.weebly.com
- fizolapojola.weebly.com
- dujewukemapaf.weebly.com
- ritibamubube.weebly.com
- gimejexoxixaza.weebly.com
- popilezofale.weebly.com
- cdn.shopify.com
- site-1043090.mozfiles.com
- site-1040136.mozfiles.com
- site-1043844.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- u:\^
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report