SUSPICIOUS — 46e9ec8.pdf
SUSPICIOUS — 46e9ec8.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (51/100). 1 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a11bd7d4d44ec932612b9063227660ab40b3e93aa32bc2549dbf292edc938a9a - SHA-1:
021f0c512857fc3ea6f29346540868354250dc62 - MD5:
7bbc1795a194df1159b752e15fc7eff0 - ssdeep:
768:1LgGzpDgpTenqwlBUSelzKVDja4u7uxDL/ftVZXGiFqNWGE3jzIc:OGF8pca4uKxHtVZLKWDzIc - TLSH:
T103307EF740A3FD8D7A8B9F03AAAA245E9189C7485133E650489C772DD0BC77E7E10950 - Submitted as: 46e9ec8.pdf
- File type: pdf · Size: 38068 bytes
- Verdict: suspicious (51/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 51/100 is the fusion of 3 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/1491136d-326e-468a-aa06-c168d08fba0e/43336578949.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=an%20introduction%20to%20language%2010th%20edition%20solutions, https://uploads.strikinglycdn.com/files/1491136d-326e-468a-aa06-c168d08fba0e/43336578949.pdf, https://uploads.strikinglycdn.com/files/5f02b751-cb78-4cef-a6bb-55bddf21b2a6/zibisomelomuxilarefuriwug.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=an%20introduction%20to%20language%2010th%20edition%20solutions
- https://uploads.strikinglycdn.com/files/1491136d-326e-468a-aa06-c168d08fba0e/43336578949.pdf
- https://uploads.strikinglycdn.com/files/5f02b751-cb78-4cef-a6bb-55bddf21b2a6/zibisomelomuxilarefuriwug.pdf
- https://uploads.strikinglycdn.com/files/f7a8ddea-4a83-4e14-9e4a-5070431215e3/60904668965.pdf
- https://cdn.shopify.com/s/files/1/0436/8377/4614/files/88660853244.pdf
- https://cdn.shopify.com/s/files/1/0462/3669/6725/files/15789709873.pdf
- https://cdn.shopify.com/s/files/1/0481/6348/7897/files/clean_master_pro_hack_apk.pdf
- https://cdn.shopify.com/s/files/1/0496/4669/8649/files/dawn_of_war_soulstorm_campaign_guide.pdf
- https://cdn.shopify.com/s/files/1/0483/5291/9703/files/17403728022.pdf
- https://cdn.shopify.com/s/files/1/0503/0307/4469/files/websphere_application_server_tutorial.pdf
- https://cdn.shopify.com/s/files/1/0497/1560/9761/files/bijopiwi.pdf
- https://cdn.shopify.com/s/files/1/0266/9677/7915/files/dremel_trsm800_straight_edge_guide.pdf
- https://uploads.strikinglycdn.com/files/e51022a4-42ad-4ff2-a122-427bf0d34c0b/96575753674.pdf
- https://uploads.strikinglycdn.com/files/04f21e76-9998-486d-a5a9-23ca3cc15d7e/the_core_competence_of_the_corporati.pdf
- https://uploads.strikinglycdn.com/files/8943dcbb-c7e7-4153-911d-1595ae35990b/39222741149.pdf
- https://uploads.strikinglycdn.com/files/bd2d2abe-32c0-428f-b3da-2cf36c79e026/zujasodiloboda.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/1867598.pdf
- https://tekegalesi.weebly.com/uploads/1/3/0/7/130740489/lunugipozepo.pdf
- https://popilezofale.weebly.com/uploads/1/3/1/1/131164236/wogajag.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/1441493.pdf
- https://jubunukaf.weebly.com/uploads/1/3/1/4/131483214/8710936.pdf
- https://cdn.shopify.com/s/files/1/0481/4408/9255/files/bijujazug.pdf
- https://cdn.shopify.com/s/files/1/0484/1016/5416/files/international_thespian_society.pdf
- https://cdn.shopify.com/s/files/1/0432/2535/0301/files/94074127941.pdf
- https://cdn.shopify.com/s/files/1/0266/8757/0105/files/nelugoxobujuxiriguxoz.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- vuxozajuje.weebly.com
- tekegalesi.weebly.com
- popilezofale.weebly.com
- xojerajap.weebly.com
- jubunukaf.weebly.com
- findtestbanks.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report