SUSPICIOUS — 4f559dbb.pdf
SUSPICIOUS — 4f559dbb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d8558c628900a372a9f47ae9586068b973f83efdebfda7bb4c835b68e808ec68 - SHA-1:
e290b74fbe62a6f9c7c84977fc691ef5c8cf7b44 - MD5:
5539ca86b39fc4d03dda3f22750e7e1e - ssdeep:
768:ogGzpDRpt56LXq4KKnTkdmLb/F0sSzGOO+F0dSym18yjKdrpIl5c8oWx/Z9lI95J:lGFtpt5s4dRFuSsyapHAbI952Ur - TLSH:
T13A328DF710E3ED8CBA8A9B13ADB724AA558DC38D71269B54848C7B2DC07C5BD6E10C50 - Submitted as: 4f559dbb.pdf
- File type: pdf · Size: 43967 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/gapovowumepekegosiza.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=robinson%20crusoe%20study%20guide, https://site-1040428.mozfiles.com/files/1040428/kofebebinuluruga.pdf, https://site-1043647.mozfiles.com/files/1043647/woverasukev.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=robinson%20crusoe%20study%20guide
- https://site-1040428.mozfiles.com/files/1040428/kofebebinuluruga.pdf
- https://site-1043647.mozfiles.com/files/1043647/woverasukev.pdf
- https://site-1041169.mozfiles.com/files/1041169/85537117673.pdf
- https://uploads.strikinglycdn.com/files/c78406d6-c725-4b52-894c-caae5ab244e4/doruvonelujoj.pdf
- https://uploads.strikinglycdn.com/files/125f4b04-14c9-4fc5-aa4f-c080c183319e/robiparinebapibiviwijebul.pdf
- https://uploads.strikinglycdn.com/files/3f9c0cb8-4e36-4dd9-b2f9-d80a14fff803/jiseveratuluninipevinuk.pdf
- https://uploads.strikinglycdn.com/files/f1d19d8f-445e-496b-a2c5-62144ce3a23f/mikekarugujaj.pdf
- https://viwuwobigoku.weebly.com/uploads/1/3/1/3/131378942/nilatoj-lumuk-lulexupiteleg-viwaz.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/gapovowumepekegosiza.pdf
- https://mupibidegupek.weebly.com/uploads/1/3/0/8/130874042/6752891a.pdf
- https://tiposowa.weebly.com/uploads/1/3/1/1/131164246/6101509.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/1109957.pdf
- https://cdn.shopify.com/s/files/1/0484/8012/5082/files/accessory_not_supported_headphones_android.pdf
- https://cdn.shopify.com/s/files/1/0480/6636/3546/files/5691620731.pdf
- https://cdn.shopify.com/s/files/1/0429/9289/4105/files/22988861460.pdf
- https://cdn-cms.f-static.net/uploads/4365562/normal_5f872184819c2.pdf
- https://cdn-cms.f-static.net/uploads/4368501/normal_5f877fb6c14e0.pdf
- https://cdn-cms.f-static.net/uploads/4366389/normal_5f8753f73ce44.pdf
- https://cdn-cms.f-static.net/uploads/4366344/normal_5f87b2cfaf3d7.pdf
- https://cdn-cms.f-static.net/uploads/4368750/normal_5f880049c33dc.pdf
- https://uploads.strikinglycdn.com/files/27e7fe5b-a0d2-4e79-b17e-a41d627cfc7f/21949317359.pdf
- https://uploads.strikinglycdn.com/files/d3c0cab0-6042-4584-97d3-1ea55bb9dd8e/gapusofusokatudizede.pdf
- https://uploads.strikinglycdn.com/files/61986b33-1806-4c36-b8e9-3e387d951b02/sadizadivu.pdf
- https://uploads.strikinglycdn.com/files/ec514b4c-6af6-4426-a2a1-27a895b72e76/27031888561.pdf
Embedded domains
- cctraff.ru
- site-1040428.mozfiles.com
- site-1043647.mozfiles.com
- site-1041169.mozfiles.com
- uploads.strikinglycdn.com
- viwuwobigoku.weebly.com
- genigudepa.weebly.com
- mupibidegupek.weebly.com
- tiposowa.weebly.com
- bedizegoresupa.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report