SUSPICIOUS — dc35c0.pdf
SUSPICIOUS — dc35c0.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e4dad9555b997b46c60fa19b013ea68a5dbbacb2ea0e891efb54c2831aa5d501 - SHA-1:
0c6cd58fce155ef1cc92fb811fe80e77eb4484b9 - MD5:
ee6d16b510e720941d0d4710da195b0e - ssdeep:
768:SgGzpDjpRs/zhT/rG6ta2stYcSYM3epio7Yagg:PGFvpa863s6Rupio7Yagg - TLSH:
T1EE319EF31493DC4CBA8A67539DEB10A9558EC38C6137E750948C372E91BC6EEAF10960 - Submitted as: dc35c0.pdf
- File type: pdf · Size: 42439 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/76dce8b1-6f73-4071-9c56-ae7e8f83fe7c/42585621893.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=public%20speaking%20for%20dummies%20pdf, https://uploads.strikinglycdn.com/files/76dce8b1-6f73-4071-9c56-ae7e8f83fe7c/42585621893.pdf, https://uploads.strikinglycdn.com/files/707f1ec2-63da-4801-b3d1-7d109c876f62/88503262208.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=public%20speaking%20for%20dummies%20pdf
- https://uploads.strikinglycdn.com/files/76dce8b1-6f73-4071-9c56-ae7e8f83fe7c/42585621893.pdf
- https://uploads.strikinglycdn.com/files/707f1ec2-63da-4801-b3d1-7d109c876f62/88503262208.pdf
- https://uploads.strikinglycdn.com/files/53346fbe-fac6-4097-8bb4-b59600b49799/sosamasutanadebeduwodiriv.pdf
- https://uploads.strikinglycdn.com/files/6ee6efff-699b-41d6-b13e-d73127520c4b/perozalesizuzisawuguxor.pdf
- https://uploads.strikinglycdn.com/files/84b30a54-da07-456d-83b8-0df6f303f4f8/85104397019.pdf
- https://site-1041291.mozfiles.com/files/1041291/94440172246.pdf
- https://site-1040681.mozfiles.com/files/1040681/29280985424.pdf
- https://uploads.strikinglycdn.com/files/ea708d33-b612-44e7-8484-ed668399b3a2/bolukufojitarurifuvapimon.pdf
- https://uploads.strikinglycdn.com/files/8fa0acf6-8bb9-47fc-a4fd-bf845e5af1e7/sobevimipalusuwororekejen.pdf
- https://uploads.strikinglycdn.com/files/b367f3cc-4b60-46f5-bcba-1ab8099dca71/43891511191.pdf
- https://uploads.strikinglycdn.com/files/b33adacb-cf9c-46c6-a918-cca6eba9b775/gukokodenisu.pdf
- https://uploads.strikinglycdn.com/files/8c886391-0d39-4411-8159-a2af05a57afc/lifovipevuvoda.pdf
- https://uploads.strikinglycdn.com/files/8356bdba-ec91-44de-88b7-0b43c8b06e3e/50177977148.pdf
- https://uploads.strikinglycdn.com/files/a2731a64-9d64-48ec-bf2f-1115babe4a0e/87116024179.pdf
- https://uploads.strikinglycdn.com/files/3ca327ce-0ff2-4097-83c0-245b8fa258c5/10238670623.pdf
- https://uploads.strikinglycdn.com/files/f6e688fe-7b91-4bb5-ab43-97914e02a6f8/30175242472.pdf
- https://site-1039999.mozfiles.com/files/1039999/nojofajuwanozegekigolebe.pdf
- https://site-1042498.mozfiles.com/files/1042498/fulisofomojamubudazope.pdf
- https://site-1038909.mozfiles.com/files/1038909/72455060669.pdf
- https://site-1042990.mozfiles.com/files/1042990/ripawavekovemiv.pdf
- https://site-1039235.mozfiles.com/files/1039235/49974448121.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/2122744.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/vunidixeviro_xitosujitupile_kadape.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1041291.mozfiles.com
- site-1040681.mozfiles.com
- site-1039999.mozfiles.com
- site-1042498.mozfiles.com
- site-1038909.mozfiles.com
- site-1042990.mozfiles.com
- site-1039235.mozfiles.com
- xojerajap.weebly.com
- bedizegoresupa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- b:\`
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report