SUSPICIOUS — 7352782.pdf
SUSPICIOUS — 7352782.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
04ac4b07018c20bc1d4a8d91dccc86eaa14ae26f0fa1f3d097faa833782b8fe8 - SHA-1:
8e149dcaa348af6673e993c62be41d823f0113d0 - MD5:
2278127f79fab6c6b66de02d170bb534 - ssdeep:
768:igGzpDdpUP+nBfAqbR2mJKZ5Q8feHjtFRbrc/jFiDVzWb:/GFJpbKZBfMlgjIzWb - TLSH:
T103328EF360A7EE8C3A8B5F53AD6611986449C68D2137D3A05488761CD4BCAFD6F00A61 - Submitted as: 7352782.pdf
- File type: pdf · Size: 43488 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/eb10ea1f-53c9-49c5-a40b-4674275c1b7f/73022488876.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=sud%20ouest%20bearn%20et%20soule%20orthez, https://uploads.strikinglycdn.com/files/b3a2e9cf-9664-4436-99cf-bb348a6cc2be/xines.pdf, https://uploads.strikinglycdn.com/files/ddd461c0-19cd-4472-b24c-0a337a058d6e/83586695328.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=sud%20ouest%20bearn%20et%20soule%20orthez
- https://uploads.strikinglycdn.com/files/b3a2e9cf-9664-4436-99cf-bb348a6cc2be/xines.pdf
- https://uploads.strikinglycdn.com/files/ddd461c0-19cd-4472-b24c-0a337a058d6e/83586695328.pdf
- https://uploads.strikinglycdn.com/files/eb10ea1f-53c9-49c5-a40b-4674275c1b7f/73022488876.pdf
- https://cdn-cms.f-static.net/uploads/4368736/normal_5f89b161372df.pdf
- https://cdn-cms.f-static.net/uploads/4365642/normal_5f873c0abcf34.pdf
- https://cdn-cms.f-static.net/uploads/4371809/normal_5f899a9e8a531.pdf
- https://uploads.strikinglycdn.com/files/48691bab-36b8-4c77-baa7-d7cd48bc0de4/bilabisumobawutifomaze.pdf
- https://uploads.strikinglycdn.com/files/78ce2eda-550c-4cb2-8678-f24d455a7793/kalekolajotikagotel.pdf
- https://cdn-cms.f-static.net/uploads/4366664/normal_5f8918a34feca.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f86f53751ac3.pdf
- https://cdn-cms.f-static.net/uploads/4367287/normal_5f88a2d96c728.pdf
- https://cdn-cms.f-static.net/uploads/4371495/normal_5f886189866b5.pdf
- https://cdn-cms.f-static.net/uploads/4374189/normal_5f89fc9741a01.pdf
- https://cdn.shopify.com/s/files/1/0481/8717/9160/files/scion_tc_dezod_turbo_kit.pdf
- https://cdn.shopify.com/s/files/1/0482/9016/8987/files/fipibukakox.pdf
- https://uploads.strikinglycdn.com/files/c89ea1d6-b138-4b46-a9b3-b2c0873b7933/jotujo.pdf
- https://uploads.strikinglycdn.com/files/3755ff2a-90fa-4318-8f10-150a46f1b8cd/zujupixivotalosovufudibi.pdf
- https://uploads.strikinglycdn.com/files/3d5780ee-6520-4068-8606-1e467f6800da/vidolunogedimilemij.pdf
- https://uploads.strikinglycdn.com/files/69c8c050-d06f-4a58-bee6-3a33a1532c5e/59096669812.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report