SUSPICIOUS — f15f122f7545534.pdf
SUSPICIOUS — f15f122f7545534.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f6b4697610bbb2677bed8b37b190688ad4eb04e091a04d013f54a34b25305b02 - SHA-1:
20ecadadb6fcba90c0545cec4e6f8dc08e04d7e8 - MD5:
3ee7fa816da890cd10e7947d12d01026 - ssdeep:
768:azgGzpDMpf0hhsnLEQEI0G2nbZOK+H66Av+AAYryfzEzV0hq3gKPVc1SoOSZd:9GFApcx5M69AMWzEzSqQEc1SoOSZd - TLSH:
T1F3328EF704A7DD4C7A876B839EFB05A45549C288722797A144CC776DC8BC2BCAF10960 - Submitted as: f15f122f7545534.pdf
- File type: pdf · Size: 44444 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/cadbb86c-7e9d-481c-adc2-65f44433165e/dukabuwebaloboresudonim.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=damonps2%20emulador%20livre, https://cdn-cms.f-static.net/uploads/4366335/normal_5f874fff0ce90.pdf, https://cdn-cms.f-static.net/uploads/4367668/normal_5f8900f0993e3.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=damonps2%20emulador%20livre
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f874fff0ce90.pdf
- https://cdn-cms.f-static.net/uploads/4367668/normal_5f8900f0993e3.pdf
- https://cdn-cms.f-static.net/uploads/4365657/normal_5f875c3955277.pdf
- https://cdn-cms.f-static.net/uploads/4366381/normal_5f88f7086c725.pdf
- https://cdn-cms.f-static.net/uploads/4366646/normal_5f87c3d165257.pdf
- https://uploads.strikinglycdn.com/files/d4a7e8d6-42c5-4fae-bf99-e7fd7f41b959/xositiroso.pdf
- https://uploads.strikinglycdn.com/files/cadbb86c-7e9d-481c-adc2-65f44433165e/dukabuwebaloboresudonim.pdf
- https://uploads.strikinglycdn.com/files/0aa3d78c-ab2a-4981-afb5-e88983d13557/bajadokidelusi.pdf
- https://uploads.strikinglycdn.com/files/e4f47484-1078-45fe-8404-6a8068288928/46808917197.pdf
- https://uploads.strikinglycdn.com/files/e9cf2807-72cc-43e6-8382-e39253eab59b/43555513014.pdf
- https://uploads.strikinglycdn.com/files/4562a998-cbc9-4883-b46a-ab732e9207d6/10912869817.pdf
- https://uploads.strikinglycdn.com/files/a38b9748-6a6f-41d4-a7e2-c99fc3eae04d/togidewus.pdf
- https://site-1037187.mozfiles.com/files/1037187/fomilalomumagojumi.pdf
- https://site-1040438.mozfiles.com/files/1040438/59483338777.pdf
- https://site-1042287.mozfiles.com/files/1042287/35566358610.pdf
- https://site-1039607.mozfiles.com/files/1039607/76394304860.pdf
- https://lipowuripipu.weebly.com/uploads/1/3/1/3/131378852/lupefesosite-rofakewawi-nanoti.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/8448799.pdf
- https://tejigenunonim.weebly.com/uploads/1/3/0/8/130813632/eecc1.pdf
- https://uploads.strikinglycdn.com/files/13f0c0a4-482d-4f6c-807d-2930c95f2ae1/46087176262.pdf
- https://uploads.strikinglycdn.com/files/3c336292-a839-424f-b4e2-d1b4ede40664/72201245847.pdf
- https://uploads.strikinglycdn.com/files/8231efde-5389-40f9-bd4f-6ec0009c4c8b/3746992129.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1037187.mozfiles.com
- site-1040438.mozfiles.com
- site-1042287.mozfiles.com
- site-1039607.mozfiles.com
- lipowuripipu.weebly.com
- wepugimi.weebly.com
- tejigenunonim.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report