SUSPICIOUS — 91acb.pdf
SUSPICIOUS — 91acb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
575cb07334eff17f39b896215f22152aa30cdae1c91ed11203969a48b72ce522 - SHA-1:
7f15cc5f5100f1e4dff32bda83d6e3cbc7fa8161 - MD5:
f1d054cd9e38b64bdb74f02961de0393 - ssdeep:
768:WgGzpDfpwl3z/U/XCHgoPYWfnlJ60F1I3VNer4Tqgo5u+SmeG79kq8uw:DGFjpiUXEnPPXF1I3VFTqgoQbW9kq8uw - TLSH:
T171339EF310A3ED8C7B8B5B139EAB1069514AD74DA036D76044887B2CC4BC6FD3E11A25 - Submitted as: 91acb.pdf
- File type: pdf · Size: 48206 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://wedebiki.weebly.com/uploads/1/3/0/9/130969436/dcefeca.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=ask%20and%20it%20is%20given%20pdf, https://purolejomi.weebly.com/uploads/1/3/0/7/130776639/goxonel.pdf, https://wedebiki.weebly.com/uploads/1/3/0/9/130969436/dcefeca.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=ask%20and%20it%20is%20given%20pdf
- https://purolejomi.weebly.com/uploads/1/3/0/7/130776639/goxonel.pdf
- https://wedebiki.weebly.com/uploads/1/3/0/9/130969436/dcefeca.pdf
- https://vupimolafi.weebly.com/uploads/1/3/1/3/131398504/34df368c5720.pdf
- https://vopevejefed.weebly.com/uploads/1/3/1/6/131606133/6649f5.pdf
- https://uploads.strikinglycdn.com/files/8c6aeaff-5722-401a-ad24-e27818a6fcd5/gezujirezujubobijar.pdf
- https://uploads.strikinglycdn.com/files/5323503b-e0b1-43a8-be44-7f2f4425673b/kuvokevexuvitufuzulerowe.pdf
- https://uploads.strikinglycdn.com/files/a3a385f9-8c61-4122-aa44-cf074ec006b7/50325405964.pdf
- https://uploads.strikinglycdn.com/files/a17cfa5e-539b-49a8-b6b1-aced6140d2ed/xapotidutiravuveterok.pdf
- https://uploads.strikinglycdn.com/files/79431efd-6c84-4727-b75c-baf240a9a4b6/wedowijufe.pdf
- https://uploads.strikinglycdn.com/files/24130318-e710-41ab-819e-cf9c6ac2728a/51609756835.pdf
- https://uploads.strikinglycdn.com/files/542bfa33-5c96-4e84-92ce-061e2ec814e8/68285288380.pdf
- https://uploads.strikinglycdn.com/files/9bc0f0cf-0f15-44b5-b4be-919100754b0a/rexeniwufazosebamir.pdf
- https://uploads.strikinglycdn.com/files/25986452-4bff-4fee-8649-9c7402244908/tuwolasonanozikutub.pdf
- https://cdn-cms.f-static.net/uploads/4365638/normal_5f86ff8501e40.pdf
- https://cdn-cms.f-static.net/uploads/4368228/normal_5f8762131ca56.pdf
- https://cdn-cms.f-static.net/uploads/4366659/normal_5f87216489a38.pdf
- https://cdn-cms.f-static.net/uploads/4365601/normal_5f872da468708.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/9276785.pdf
- https://meporolokiso.weebly.com/uploads/1/3/2/6/132681401/8577470.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/b919b1ed8f.pdf
- https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/fd9fe9.pdf
- https://viwuwobigoku.weebly.com/uploads/1/3/1/3/131378942/juniwotusupuvafodif.pdf
- https://xawuwotogot.weebly.com/uploads/1/3/2/6/132695388/nijade_katonexabokaj_mavol.pdf
- https://porelananov.weebly.com/uploads/1/3/0/7/130775759/kozexafon.pdf
Embedded domains
- cctraff.ru
- purolejomi.weebly.com
- wedebiki.weebly.com
- vupimolafi.weebly.com
- vopevejefed.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- dutitujazekap.weebly.com
- meporolokiso.weebly.com
- zoxuzuxebexot.weebly.com
- kabudededawizo.weebly.com
- viwuwobigoku.weebly.com
- xawuwotogot.weebly.com
- porelananov.weebly.com
- rewemekekebaz.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report