SUSPICIOUS — 65fe53c16ef2d2c.pdf
SUSPICIOUS — 65fe53c16ef2d2c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9ca874db2ecf616dbd1686e367c7f7fc25640f61df6e34a5d377c655fc3b728a - SHA-1:
68f06d75a6839f62afbbcba9f303486cc5a49b7a - MD5:
48c8352dd0157393de22efcf3b8c1c76 - ssdeep:
1536:XGFIpWIwtxyT2jT5+4GAAbo61o5rnWcduM:2FIpMtxyMxrAboFScT - TLSH:
T1D535CFF314A7EC8C76CBAB136DEA2859A18AE7491036E7604498773CC4BC6FD2E50911 - Submitted as: 65fe53c16ef2d2c.pdf
- File type: pdf · Size: 58872 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://riwisasivituw.weebly.com/uploads/1/3/1/0/131070703/5644f9eb0f27e.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=integer%20games%20for%20middle%20school, https://uploads.strikinglycdn.com/files/541b3b38-d019-4ff2-b9ee-1355b24e8a85/pauvre_petit_garon_texte.pdf, https://uploads.strikinglycdn.com/files/45d76025-b3ea-46db-a137-19ab6436bfda/sozom.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=integer%20games%20for%20middle%20school
- https://uploads.strikinglycdn.com/files/541b3b38-d019-4ff2-b9ee-1355b24e8a85/pauvre_petit_garon_texte.pdf
- https://uploads.strikinglycdn.com/files/45d76025-b3ea-46db-a137-19ab6436bfda/sozom.pdf
- https://uploads.strikinglycdn.com/files/f470475b-58db-4774-a3e6-606140b6c397/36840196997.pdf
- https://uploads.strikinglycdn.com/files/e2e429d3-0af1-4151-89ea-a041a518cd1b/zagirupe.pdf
- https://cdn-cms.f-static.net/uploads/4366000/normal_5f87045cc7312.pdf
- https://cdn-cms.f-static.net/uploads/4377931/normal_5f8a798744cd9.pdf
- https://cdn-cms.f-static.net/uploads/4379363/normal_5f8a9bfb02941.pdf
- https://cdn-cms.f-static.net/uploads/4367617/normal_5f89dcc93387f.pdf
- https://riwisasivituw.weebly.com/uploads/1/3/1/0/131070703/5644f9eb0f27e.pdf
- https://koxoganonigowup.weebly.com/uploads/1/3/1/4/131408343/5128497.pdf
- https://vafuzetok.weebly.com/uploads/1/3/2/7/132740798/kegokevix.pdf
- https://pepotoxuxomupav.weebly.com/uploads/1/3/1/4/131483830/maxuwuxip.pdf
- https://tabogivazosepa.weebly.com/uploads/1/3/1/8/131871767/dowuda-dawob-vadiv.pdf
- https://kuromazu.weebly.com/uploads/1/3/2/6/132695519/186c67.pdf
- https://cdn.shopify.com/s/files/1/0493/0886/0575/files/ramirinasesifija.pdf
- https://cdn.shopify.com/s/files/1/0487/0432/3734/files/isosceles_and_equilateral_triangles_worksheet_find_the_value_of_x_and_y_answers.pdf
- https://cdn.shopify.com/s/files/1/0266/7790/3551/files/gigimanekaz.pdf
- https://cdn.shopify.com/s/files/1/0479/6727/3127/files/62172484023.pdf
- https://cdn.shopify.com/s/files/1/0495/2309/7766/files/piresapaj.pdf
- https://cdn.shopify.com/s/files/1/0428/9085/4566/files/vadirulaponutudepi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- riwisasivituw.weebly.com
- koxoganonigowup.weebly.com
- vafuzetok.weebly.com
- pepotoxuxomupav.weebly.com
- tabogivazosepa.weebly.com
- kuromazu.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report