SUSPICIOUS — 1f21eb966cf8.pdf
SUSPICIOUS — 1f21eb966cf8.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e8488e0758f05ae26b7daad91ee8722705f2ddfc6affc1d3082ce154bed21495 - SHA-1:
55749322b4a2e73041da0b246458bcc6e09421ef - MD5:
90edf8ec1a86c33d86c4360ca6cc5fb7 - ssdeep:
768:3gGzpDbpEankGxTxCchA8OwSYFct0FA6xKxn0+s/cef9PQsDF5F/BzG9Gz3es:QGFHpnCch9lFFcGHg0+QRPNDfFJfes - TLSH:
T1F0317DF34567EE4C7FC79B83A9AA29856145C78CA233A3604589372CC57C2BDBF00462 - Submitted as: 1f21eb966cf8.pdf
- File type: pdf · Size: 42394 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://cdn-cms.f-static.net/uploads/4368742/normal_5f878e935eb20.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=persona%20juridica%20y%20persona%20moral%20diferencias, https://site-1042884.mozfiles.com/files/1042884/51465995564.pdf, https://site-1039215.mozfiles.com/files/1039215/ruzerozizotogetofilo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=persona%20juridica%20y%20persona%20moral%20diferencias
- https://site-1042884.mozfiles.com/files/1042884/51465995564.pdf
- https://site-1039215.mozfiles.com/files/1039215/ruzerozizotogetofilo.pdf
- https://site-1039675.mozfiles.com/files/1039675/44903137588.pdf
- https://cdn-cms.f-static.net/uploads/4368742/normal_5f878e935eb20.pdf
- https://cdn.shopify.com/s/files/1/0496/4519/1331/files/zelda_gba_rom_hacks.pdf
- https://cdn.shopify.com/s/files/1/0499/1084/1512/files/61080183880.pdf
- https://cdn.shopify.com/s/files/1/0492/3008/6297/files/religion_in_spanish.pdf
- https://cdn.shopify.com/s/files/1/0483/0376/7715/files/jekananejo.pdf
- https://site-1039270.mozfiles.com/files/1039270/76606895394.pdf
- https://site-1040221.mozfiles.com/files/1040221/heritage_bank_app_for_android.pdf
- https://site-1042869.mozfiles.com/files/1042869/63426351482.pdf
- https://site-1036735.mozfiles.com/files/1036735/rapete.pdf
- https://fanavepuru.weebly.com/uploads/1/3/1/8/131871984/potutebemar_jotosonuzevuje_wopaxit_povabegi.pdf
- https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/6263159.pdf
- https://debasomi.weebly.com/uploads/1/3/0/7/130739769/f4455c7c2dea9a2.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/4503832.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1042884.mozfiles.com
- site-1039215.mozfiles.com
- site-1039675.mozfiles.com
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1039270.mozfiles.com
- site-1040221.mozfiles.com
- site-1042869.mozfiles.com
- site-1036735.mozfiles.com
- fanavepuru.weebly.com
- babikovinemixe.weebly.com
- debasomi.weebly.com
- vozunutav.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report