SUSPICIOUS — pezad.pdf
SUSPICIOUS — pezad.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
05b25671b6f6cac46176f142b9e8932775b3609c8aa9f7392addcbaf96270e1c - SHA-1:
026555adfb6dc1decfe45030af5d670926cdab67 - MD5:
c811371962e11fe1608c4dfa461a53ab - ssdeep:
1536:mGFVrG64p7hAhzumG8NoXgq67pe1jth6feW:/FVrG6o7hA84+XT601qD - TLSH:
T19137D0F36083ED0C7986EF176DE9696D6089E78D6132A7A40088272DC1FC7BC3D519A1 - Submitted as: pezad.pdf
- File type: pdf · Size: 75965 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/c9304702-1766-4ee7-9de1-a586805b55a6/80068900800.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=special%20education%20pdf%20download, https://uploads.strikinglycdn.com/files/c9304702-1766-4ee7-9de1-a586805b55a6/80068900800.pdf, https://uploads.strikinglycdn.com/files/288217af-5b61-4efd-9b5f-d50c5f720cfb/82332579083.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=special%20education%20pdf%20download
- https://uploads.strikinglycdn.com/files/c9304702-1766-4ee7-9de1-a586805b55a6/80068900800.pdf
- https://uploads.strikinglycdn.com/files/288217af-5b61-4efd-9b5f-d50c5f720cfb/82332579083.pdf
- https://uploads.strikinglycdn.com/files/24bc8d6f-e64d-462f-a3ad-889c2622e65e/vojubiweluvogu.pdf
- https://uploads.strikinglycdn.com/files/5783a746-cd6c-43f9-b295-dd3510b335ac/eu4_inland_seas.pdf
- https://cdn-cms.f-static.net/uploads/4403951/normal_5f91a05102c5b.pdf
- https://cdn-cms.f-static.net/uploads/4370269/normal_5f881a5545502.pdf
- https://cdn-cms.f-static.net/uploads/4383314/normal_5f90e15b49156.pdf
- https://s3.amazonaws.com/lanorolowu/5020481379.pdf
- https://s3.amazonaws.com/wilugugo/vefugabasowiv.pdf
- https://cdn.shopify.com/s/files/1/0437/2919/1066/files/use_of_english_exercises_advanced.pdf
- https://cdn.shopify.com/s/files/1/0440/8321/6549/files/25594307430.pdf
- https://cdn.shopify.com/s/files/1/0500/0308/3424/files/luxile.pdf
- https://cdn.shopify.com/s/files/1/0437/7831/0295/files/romeo_and_juliet_act_1_practice_test.pdf
- https://cdn-cms.f-static.net/uploads/4383572/normal_5f8e97734ca74.pdf
- https://cdn-cms.f-static.net/uploads/4394066/normal_5f8ec315abb52.pdf
- https://cdn-cms.f-static.net/uploads/4404959/normal_5f9382742082e.pdf
- https://cdn-cms.f-static.net/uploads/4365576/normal_5f8d0b5795b12.pdf
- https://cdn-cms.f-static.net/uploads/4410020/normal_5f9354189c8b6.pdf
- https://cdn-cms.f-static.net/uploads/4368479/normal_5f8a636c7d1a8.pdf
- https://cdn-cms.f-static.net/uploads/4371509/normal_5f8ad66759dff.pdf
- https://cdn-cms.f-static.net/uploads/4367903/normal_5f89fd3d9050f.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report