SUSPICIOUS — 20e96c8807.pdf
SUSPICIOUS — 20e96c8807.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e0665ed68a4685273d155d96241fb2e67c032579d9de356543f99153a866cc81 - SHA-1:
6b25571b106b2b972fad903f754da2c7e1063e0c - MD5:
a89d6045215d0797be2664848c4bfd4d - ssdeep:
768:qgGzpD7pxGph89/QRGW4f3AgjSZqCv/cRko3cIqFqAAWhW:3GFvpeRbCfjSZqCv/ekos6AAWhW - TLSH:
T1FD329DF340A3EE4C7E8B9B53ADA712556549C388B2278760458D3B6CC5BC6BD7F00921 - Submitted as: 20e96c8807.pdf
- File type: pdf · Size: 44055 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/dukemapa.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=hormigon%20h%2025%20caracteristicas%20do, https://cdn-cms.f-static.net/uploads/4365591/normal_5f876cc7ba021.pdf, https://cdn-cms.f-static.net/uploads/4366366/normal_5f87207911cca.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=hormigon%20h%2025%20caracteristicas%20do
- https://cdn-cms.f-static.net/uploads/4365591/normal_5f876cc7ba021.pdf
- https://cdn-cms.f-static.net/uploads/4366366/normal_5f87207911cca.pdf
- https://cdn-cms.f-static.net/uploads/4366003/normal_5f8748192c25c.pdf
- https://cdn-cms.f-static.net/uploads/4366381/normal_5f874d955f16e.pdf
- https://site-1043395.mozfiles.com/files/1043395/47425483703.pdf
- https://site-1038759.mozfiles.com/files/1038759/nofatapawobinu.pdf
- https://cdn-cms.f-static.net/uploads/4366993/normal_5f874494c7809.pdf
- https://cdn-cms.f-static.net/uploads/4366302/normal_5f877e731f0b5.pdf
- https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/dukemapa.pdf
- https://pumowurunumig.weebly.com/uploads/1/3/2/7/132740285/d1db2.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/5473886.pdf
- https://uploads.strikinglycdn.com/files/9cfd419d-1788-4f72-bcb8-2bd65eaaf0ae/39693040253.pdf
- https://uploads.strikinglycdn.com/files/1a388fa7-d163-428a-be14-e0331f36d85c/68863575433.pdf
- https://uploads.strikinglycdn.com/files/7173879c-c4ab-4c39-8079-d9ec39bb5f59/14993561602.pdf
- https://uploads.strikinglycdn.com/files/75683438-50b9-4df6-ac28-a162cf49ac9a/tojosalagiw.pdf
- https://uploads.strikinglycdn.com/files/c71b6d5a-536d-490e-8303-714634973c1b/99062749159.pdf
- https://site-1040685.mozfiles.com/files/1040685/awk_command_tutorial.pdf
- https://site-1042498.mozfiles.com/files/1042498/zulilegopozepanulomevelub.pdf
- https://site-1041946.mozfiles.com/files/1041946/53832870729.pdf
- https://site-1043887.mozfiles.com/files/1043887/9704790058.pdf
- https://site-1044455.mozfiles.com/files/1044455/potamafemunagivazovimesut.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- site-1043395.mozfiles.com
- site-1038759.mozfiles.com
- nudojafobedem.weebly.com
- pumowurunumig.weebly.com
- bedizegoresupa.weebly.com
- uploads.strikinglycdn.com
- site-1040685.mozfiles.com
- site-1042498.mozfiles.com
- site-1041946.mozfiles.com
- site-1043887.mozfiles.com
- site-1044455.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report