SUSPICIOUS — f0272.pdf
SUSPICIOUS — f0272.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a92b81ad90669fdfaa9c38344f0ed5a9a035629b78bbb8b4a8ad33f6b58ec46b - SHA-1:
a531f889037e77deb69a2b65ff3fbbad2773c58b - MD5:
35909f78936dd7872995e83a349a7f60 - ssdeep:
768:UgGzpD9etyLT/uW9A7EtbumdwrtoqQTrwtai2+Ryelyt:hGFhetSImmrwfwtaZ+5lyt - TLSH:
T130338DF350E7ED8C7AC6AB4399EB1148944AC78C6137E75004987B3CD4BC6ED6E10A61 - Submitted as: f0272.pdf
- File type: pdf · Size: 48947 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://vimiwegom.weebly.com/uploads/1/3/0/7/130775837/guliwok.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=kmbc%20first%20alert%20weather%20app, https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/4102594.pdf, https://runebipunozup.weebly.com/uploads/1/3/1/4/131406604/324248c1e1a.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=kmbc%20first%20alert%20weather%20app
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/4102594.pdf
- https://runebipunozup.weebly.com/uploads/1/3/1/4/131406604/324248c1e1a.pdf
- https://zugufavowi.weebly.com/uploads/1/3/0/8/130874222/moximajiwabeter.pdf
- https://uploads.strikinglycdn.com/files/cb6457cb-9679-4fd1-9214-3f8da562ce0e/59330943234.pdf
- https://uploads.strikinglycdn.com/files/ad915ee6-c8c2-4256-bf4a-ea933bf555ed/sadanebulelixelowemu.pdf
- https://uploads.strikinglycdn.com/files/1ca79862-7a3d-4d26-854a-008d35670545/pulixevabona.pdf
- https://medizagokitoni.weebly.com/uploads/1/3/2/3/132303310/6131267.pdf
- https://vimiwegom.weebly.com/uploads/1/3/0/7/130775837/guliwok.pdf
- https://biwugina.weebly.com/uploads/1/3/1/1/131163984/zivope_sovelidoba.pdf
- https://natizupasa.weebly.com/uploads/1/3/1/4/131437725/jukos-wewatinexa.pdf
- https://uploads.strikinglycdn.com/files/3bd14d05-886c-4dc9-925f-2817540bccb7/lobopi.pdf
- https://uploads.strikinglycdn.com/files/1e14e450-51a6-4994-92b2-91d4cf8b5155/21183559551.pdf
- https://cdn.shopify.com/s/files/1/0435/1305/3343/files/18448820538.pdf
- https://cdn.shopify.com/s/files/1/0433/6916/9054/files/37914708705.pdf
- https://cdn.shopify.com/s/files/1/0430/3778/6265/files/wedge-tailed_eagle_vs_kangaroo.pdf
- https://cdn.shopify.com/s/files/1/0501/8304/5293/files/i_am_paul_walker_tv_guide.pdf
- https://uploads.strikinglycdn.com/files/393cb308-a62b-498c-9188-a172a76d4cf8/xarotonunizebadi.pdf
- https://uploads.strikinglycdn.com/files/c2a30bfe-56fe-45e8-9115-e1205a4230cc/67875925525.pdf
- https://uploads.strikinglycdn.com/files/d92674b4-59c9-46a0-b7b6-ed441679f893/77432763668.pdf
- https://uploads.strikinglycdn.com/files/7af4bb85-7c76-4963-a607-0fd2dd6e2d74/65929164938.pdf
- https://uploads.strikinglycdn.com/files/4d970a62-44c5-4b22-8a9b-752149e62281/xozowigifomosivolelenurup.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- mogilifus.weebly.com
- runebipunozup.weebly.com
- zugufavowi.weebly.com
- uploads.strikinglycdn.com
- medizagokitoni.weebly.com
- vimiwegom.weebly.com
- biwugina.weebly.com
- natizupasa.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report