SUSPICIOUS — 6008217.pdf
SUSPICIOUS — 6008217.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (51/100). 1 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
acd12726da14f5483072bb37dd96963da5f0674920c9948b42775744ea3563e1 - SHA-1:
2be9389f85c4fa1da8184eb14eb9da2d5d5b275f - MD5:
a8fd7df5d54ccd95564178bcb34dc930 - ssdeep:
384:tsFlS3K6XgKV7cAgdOpW+0FjpzUvMOkgtXItSKhls7kn8B3hNj9KqrvIlN5xCUSt:xgGzpDqpQv6bKXRKsIH/o5mBx/GZVo0 - TLSH:
T1C2305BF300A7ED4C7A8F6B476EEB01A86089D38D613697504498AB7DD47CABD7F10920 - Submitted as: 6008217.pdf
- File type: pdf · Size: 36363 bytes
- Verdict: suspicious (51/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 51/100 is the fusion of 3 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/dc9e0af8-8101-430b-8296-4ec16000ef7e/mafitobekawobelaj.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=manual%20trator%20ford%206600%20pdf, https://uploads.strikinglycdn.com/files/966525d1-66e4-4e3f-b595-617dba064fbf/babubilavofipejipumuvede.pdf, https://uploads.strikinglycdn.com/files/11f4289f-b3f6-4bd1-8e60-a40402d38951/38244201587.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=manual%20trator%20ford%206600%20pdf
- https://uploads.strikinglycdn.com/files/966525d1-66e4-4e3f-b595-617dba064fbf/babubilavofipejipumuvede.pdf
- https://uploads.strikinglycdn.com/files/11f4289f-b3f6-4bd1-8e60-a40402d38951/38244201587.pdf
- https://uploads.strikinglycdn.com/files/b7e7ba0f-0359-4f86-a9a2-46f8181663fe/56677507033.pdf
- https://site-1036644.mozfiles.com/files/1036644/25214401757.pdf
- https://site-1042844.mozfiles.com/files/1042844/28265465803.pdf
- https://site-1038422.mozfiles.com/files/1038422/xibutadebedajig.pdf
- https://site-1044010.mozfiles.com/files/1044010/4201455152.pdf
- https://site-1044152.mozfiles.com/files/1044152/vasabikeruxe.pdf
- https://uploads.strikinglycdn.com/files/dc9e0af8-8101-430b-8296-4ec16000ef7e/mafitobekawobelaj.pdf
- https://uploads.strikinglycdn.com/files/072549a5-9821-48b2-882c-7a96fd4d165b/bududufexuzabalatadugam.pdf
- https://uploads.strikinglycdn.com/files/fac34664-fcff-43a7-b141-f6c344158f2c/23298091189.pdf
- https://uploads.strikinglycdn.com/files/70717d9c-162e-4c04-bd6b-13ccc5fb2db7/66458738288.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/4e0d994f.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/36ce75ac.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/8742796.pdf
- https://jiwepurojal.weebly.com/uploads/1/3/0/7/130775762/jezutisokezofu.pdf
- https://taxajadotediru.weebly.com/uploads/1/3/0/8/130873824/zutabolom-neritevi-wapatokilab-nilelebatojo.pdf
- https://site-1037275.mozfiles.com/files/1037275/7355564588.pdf
- https://site-1042926.mozfiles.com/files/1042926/67723094838.pdf
- https://site-1042495.mozfiles.com/files/1042495/muwaxigexerofawuf.pdf
- https://site-1040177.mozfiles.com/files/1040177/tonorenudepep.pdf
- https://site-1036633.mozfiles.com/files/1036633/sijevolute.pdf
- https://site-1036993.mozfiles.com/files/1036993/78246121243.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1036644.mozfiles.com
- site-1042844.mozfiles.com
- site-1038422.mozfiles.com
- site-1044010.mozfiles.com
- site-1044152.mozfiles.com
- genigudepa.weebly.com
- dutitujazekap.weebly.com
- mogilifus.weebly.com
- jiwepurojal.weebly.com
- taxajadotediru.weebly.com
- site-1037275.mozfiles.com
- site-1042926.mozfiles.com
- site-1042495.mozfiles.com
- site-1040177.mozfiles.com
- site-1036633.mozfiles.com
- site-1036993.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report