SUSPICIOUS — bc162df109b50.pdf
SUSPICIOUS — bc162df109b50.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
cf471b384df8dbf5a794ec3645ea68b5f2649f67ade835efeec66d5f99a6ef63 - SHA-1:
efa29d670274d28c42eba5bd13cca1388a489d0e - MD5:
ab228403d63030cc91f2bbb5b51ad743 - ssdeep:
768:mgGzpDip0g84hPKvVfUyfu/IsVmJNWE3cAkNXmYz3eKIZtHLNGUmyztZRnWUG:zGFupTwedmTWSy1Zz3entHZNztZRnNG - TLSH:
T1DE328DF351A3DD4CBA8B5B039DBB1199A08AD24DA133A7D015CC772DC8BC6AD6F51820 - Submitted as: bc162df109b50.pdf
- File type: pdf · Size: 46227 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://cdn-cms.f-static.net/uploads/4366978/normal_5f8737e00db5b.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=defiance%202050%20fast%20travel%20locations, https://site-1038495.mozfiles.com/files/1038495/43105563133.pdf, https://site-1042725.mozfiles.com/files/1042725/new_headway_students_book_pre_intermediate.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=defiance%202050%20fast%20travel%20locations
- https://site-1038495.mozfiles.com/files/1038495/43105563133.pdf
- https://site-1042725.mozfiles.com/files/1042725/new_headway_students_book_pre_intermediate.pdf
- https://site-1041773.mozfiles.com/files/1041773/60208562696.pdf
- https://site-1041084.mozfiles.com/files/1041084/8855599936.pdf
- https://cdn-cms.f-static.net/uploads/4368955/normal_5f87b34d4a251.pdf
- https://cdn-cms.f-static.net/uploads/4366007/normal_5f871921b1e21.pdf
- https://cdn-cms.f-static.net/uploads/4366978/normal_5f8737e00db5b.pdf
- https://cdn-cms.f-static.net/uploads/4366408/normal_5f88252bb7b09.pdf
- https://cdn-cms.f-static.net/uploads/4365591/normal_5f8725dba77b7.pdf
- https://cdn-cms.f-static.net/uploads/4370764/normal_5f886d6fcce25.pdf
- https://cdn-cms.f-static.net/uploads/4368503/normal_5f887c62a13b3.pdf
- https://site-1040282.mozfiles.com/files/1040282/dobewana.pdf
- https://site-1042539.mozfiles.com/files/1042539/nefadejorobexofusomopik.pdf
- https://site-1039472.mozfiles.com/files/1039472/jezut.pdf
- https://site-1043698.mozfiles.com/files/1043698/xazefimafupikinaxowedaj.pdf
- https://texitanoz.weebly.com/uploads/1/3/0/7/130739996/dinakozipe-sosupidop.pdf
- https://wetuxabo.weebly.com/uploads/1/3/0/8/130873937/a524ba0e9d.pdf
- https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/c25f730.pdf
- https://riwisasivituw.weebly.com/uploads/1/3/1/0/131070703/lakorixa.pdf
- https://zeginuvo.weebly.com/uploads/1/3/0/7/130775519/ca867ce68ed.pdf
- https://uploads.strikinglycdn.com/files/7e953032-f01e-4c00-83d2-92554ea1a8e9/39401949203.pdf
- https://uploads.strikinglycdn.com/files/d60a2cc7-b5c7-4897-bc2a-949cd301d210/22236623350.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- site-1038495.mozfiles.com
- site-1042725.mozfiles.com
- site-1041773.mozfiles.com
- site-1041084.mozfiles.com
- cdn-cms.f-static.net
- site-1040282.mozfiles.com
- site-1042539.mozfiles.com
- site-1039472.mozfiles.com
- site-1043698.mozfiles.com
- texitanoz.weebly.com
- wetuxabo.weebly.com
- gevafitasib.weebly.com
- riwisasivituw.weebly.com
- zeginuvo.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report