SUSPICIOUS — zesobu-sagijazelore-mewifom-monolololedebam.pdf
SUSPICIOUS — zesobu-sagijazelore-mewifom-monolololedebam.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ecf3f28612a666cce3892e1299ba10aa2b0b5f061a20500f0dcf595f58910217 - SHA-1:
c94e8dd76a4d520e78e847e1f6eb83a990ae71a7 - MD5:
07b3aa9189c9a9e639b4cbd820109641 - ssdeep:
768:agGzpDEpAwR4KCJdyPS/PmTMDLNmBPb1XygqvU1bnOMty:HGFgpgqT2mz1XyLc9nOMty - TLSH:
T196307CF36097DD9CBA8B9B43ADAB14AA208AD74C107797A454CC376CC0BC6BD3E50950 - Submitted as: zesobu-sagijazelore-mewifom-monolololedebam.pdf
- File type: pdf · Size: 38426 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/c0a5f548-6925-49f8-8ed7-cb184f2b9dc4/6075279280.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=mixed%20tenses%20exercises%20pdf%20intermedi, https://uploads.strikinglycdn.com/files/c0a5f548-6925-49f8-8ed7-cb184f2b9dc4/6075279280.pdf, https://uploads.strikinglycdn.com/files/5c531cb1-0316-4b09-9b8c-bbddc3ded553/45329411927.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=mixed%20tenses%20exercises%20pdf%20intermedi
- https://uploads.strikinglycdn.com/files/c0a5f548-6925-49f8-8ed7-cb184f2b9dc4/6075279280.pdf
- https://uploads.strikinglycdn.com/files/5c531cb1-0316-4b09-9b8c-bbddc3ded553/45329411927.pdf
- https://uploads.strikinglycdn.com/files/06797366-c87f-41d5-9416-e1f36dfe2a92/85347293757.pdf
- https://uploads.strikinglycdn.com/files/155edc2c-5960-4255-adfc-f15efc543e21/62999783112.pdf
- https://uploads.strikinglycdn.com/files/fda041df-dbcc-4e0b-acf0-dfc52a6235c4/robisijedazanavi.pdf
- https://cdn.shopify.com/s/files/1/0432/0546/0125/files/ornament_storage_box_target.pdf
- https://cdn-cms.f-static.net/uploads/4365626/normal_5f86f44796a6c.pdf
- https://cdn-cms.f-static.net/uploads/4374379/normal_5f896528bef68.pdf
- https://cdn-cms.f-static.net/uploads/4367960/normal_5f88de0f12c1d.pdf
- https://uploads.strikinglycdn.com/files/89f0b1ab-e46b-4980-ab19-751c362716c1/40965579148.pdf
- https://uploads.strikinglycdn.com/files/01af8e2a-8c36-4fb0-9b35-c4341491ac7c/38894967699.pdf
- https://uploads.strikinglycdn.com/files/1989f7b1-ec59-48fa-b385-efe69833f611/49709712950.pdf
- https://uploads.strikinglycdn.com/files/e93388e8-c709-49b9-9bf8-6d4d251f69a7/nimazowodevulomepijuxato.pdf
- https://cdn-cms.f-static.net/uploads/4365659/normal_5f87019f5a819.pdf
- https://cdn-cms.f-static.net/uploads/4368505/normal_5f885dd9f4209.pdf
- https://cdn-cms.f-static.net/uploads/4372104/normal_5f88738c2eaea.pdf
- https://cdn-cms.f-static.net/uploads/4368226/normal_5f8761ee6f0ae.pdf
- https://cdn.shopify.com/s/files/1/0486/5123/9582/files/xifuko.pdf
- https://cdn.shopify.com/s/files/1/0492/0079/1715/files/9457062546.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report