SUSPICIOUS — a21786ea4c.pdf
SUSPICIOUS — a21786ea4c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d15e4580423e31b631a4854f037d042f9c2f325b72a5f9aafd40412cbc940855 - SHA-1:
df4344efc318b7a8b0b93086890caa0576d928e9 - MD5:
1e10c18623e5df2efe9eecc527e8e8f2 - ssdeep:
1536:lGFlpdkdybvSnr7/UJZekBOCTMMvRPCPjY6:4FlpCySgZnzM0R45 - TLSH:
T12834C0F3549BDC8CBBD69703AEAA109A1086D748913297F0148C7B7DC47C6EDBE10962 - Submitted as: a21786ea4c.pdf
- File type: pdf · Size: 56461 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/3dc8eacf-d906-48a2-aba6-f36f2d440b6d/49264290561.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=civ%206%20build%20city%20on%20resource, https://uploads.strikinglycdn.com/files/3dc8eacf-d906-48a2-aba6-f36f2d440b6d/49264290561.pdf, https://uploads.strikinglycdn.com/files/2becc126-59f1-427c-9df5-a610fa47e31d/55318793795.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=civ%206%20build%20city%20on%20resource
- https://uploads.strikinglycdn.com/files/3dc8eacf-d906-48a2-aba6-f36f2d440b6d/49264290561.pdf
- https://uploads.strikinglycdn.com/files/2becc126-59f1-427c-9df5-a610fa47e31d/55318793795.pdf
- https://uploads.strikinglycdn.com/files/76040079-ac25-4c8c-9b83-f5d023d2da7d/mujukuvamedira.pdf
- https://uploads.strikinglycdn.com/files/2e0279d5-f88e-4e20-82de-1363e7ea844c/tamil_alphabets.pdf
- https://uploads.strikinglycdn.com/files/48c21f16-db22-446c-b0c0-f2c47cebcd39/4725982731.pdf
- https://cdn-cms.f-static.net/uploads/4368788/normal_5f88eebdedb54.pdf
- https://uploads.strikinglycdn.com/files/7ab49a01-ce41-40e1-860c-f3478dfd041d/67492573602.pdf
- https://uploads.strikinglycdn.com/files/b022f79d-978b-460e-836a-1489e1d0e701/panasonic_dmr-hwt230eb_manual.pdf
- https://uploads.strikinglycdn.com/files/daf43aca-952c-46bf-872d-75c29c5f8317/25171784496.pdf
- https://uploads.strikinglycdn.com/files/2220dd4d-d832-4291-8a5b-9fcb4dbecf26/gikilibudivowajeke.pdf
- https://panidulupeju.weebly.com/uploads/1/3/0/9/130969186/merinorasaniv_nidikurawi_ketexirup.pdf
- https://tipefejiri.weebly.com/uploads/1/3/0/9/130969755/gasegajefiw_tazol.pdf
- https://nukubutoti.weebly.com/uploads/1/3/2/3/132302768/79c58012d3eef.pdf
- https://kubupukadumu.weebly.com/uploads/1/3/1/3/131382740/4310928.pdf
- https://saxibodusazo.weebly.com/uploads/1/3/0/7/130740440/xiluvelu.pdf
- https://s3.amazonaws.com/sugaguxagu/esl_classroom_rules.pdf
- https://s3.amazonaws.com/xarojapi/english_level_test_with_answers.pdf
- https://gogebuzavoriro.weebly.com/uploads/1/3/2/6/132681212/1b39a9d54.pdf
- https://godadonalizubo.weebly.com/uploads/1/3/1/4/131437317/3338180.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- panidulupeju.weebly.com
- tipefejiri.weebly.com
- nukubutoti.weebly.com
- kubupukadumu.weebly.com
- saxibodusazo.weebly.com
- s3.amazonaws.com
- gogebuzavoriro.weebly.com
- godadonalizubo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report