SUSPICIOUS — 2f16351a.pdf
SUSPICIOUS — 2f16351a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0a023c593aa43edaf5343a1800b8f1f26c2e1b13ba1f8ce4b89116a1a3628347 - SHA-1:
8ae241ea9d3fbf9ce013175fc58be5ef3327e6c8 - MD5:
d2629bd3b80cbf96db855001b4a9984f - ssdeep:
1536:VGF3gBGnc7AAMQRe3gl2ccg6crX4pNiRP1PF56W3fAo:oF3gYnAdMV1S9rXLRdPFXr - TLSH:
T16E39E1F74197DD0E7A835B03BAF93095658AC688262283A814DCBB3DC87C77D2E00971 - Submitted as: 2f16351a.pdf
- File type: pdf · Size: 89924 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/338f18b4-f741-47f8-86c4-8edcf7aab7d8/no_man_s_sky_paraffinium.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=the%20materialist%20conception%20of%20history%20pdf, https://cdn-cms.f-static.net/uploads/4369914/normal_5f8cefb9e460c.pdf, https://cdn-cms.f-static.net/uploads/4381964/normal_5f99ebb1367a7.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=the%20materialist%20conception%20of%20history%20pdf
- https://cdn-cms.f-static.net/uploads/4369914/normal_5f8cefb9e460c.pdf
- https://cdn-cms.f-static.net/uploads/4381964/normal_5f99ebb1367a7.pdf
- https://cdn-cms.f-static.net/uploads/4369765/normal_5f8d2582171c6.pdf
- https://uploads.strikinglycdn.com/files/338f18b4-f741-47f8-86c4-8edcf7aab7d8/no_man_s_sky_paraffinium.pdf
- https://cdn-cms.f-static.net/uploads/4420907/normal_5f998734892fa.pdf
- https://cdn.shopify.com/s/files/1/0499/7916/2775/files/endothermic_and_exothermic_reactions.pdf
- https://uploads.strikinglycdn.com/files/d53ac481-1711-4477-a96c-fb40f2cbca00/hill_climb_racing_2_mod_apk_ios.pdf
- https://cdn-cms.f-static.net/uploads/4381766/normal_5f8e278bea46c.pdf
- https://s3.amazonaws.com/zetare/acta_constitutiva_sociedad_anonima_mexico.pdf
- https://uploads.strikinglycdn.com/files/385f9dd9-8d8d-41a8-8147-7c411c36c5c9/2401609927.pdf
- https://cdn.shopify.com/s/files/1/0266/7764/1409/files/17409541191.pdf
- https://s3.amazonaws.com/jikopot/adjectif_allemand_liste.pdf
- https://uploads.strikinglycdn.com/files/865a16ca-533f-4ed6-9ddf-524e6b48e99c/3145170135.pdf
- https://cdn.shopify.com/s/files/1/0483/9669/7768/files/antique_toys_value_guide.pdf
- https://cdn-cms.f-static.net/uploads/4405674/normal_5f983a429198d.pdf
- https://uploads.strikinglycdn.com/files/3048ceec-1052-4d21-a1cf-7017900d858d/lenupabasesukufe.pdf
- https://cdn.shopify.com/s/files/1/0498/2066/3970/files/69130952981.pdf
- https://s3.amazonaws.com/sugaguxagu/jurnal_tentang_pluralisme.pdf
- https://uploads.strikinglycdn.com/files/7c2c2f0c-51a6-4f8f-8d6c-4ddb61beba6c/ziruz.pdf
- https://cdn-cms.f-static.net/uploads/4383679/normal_5f97faab43978.pdf
- https://uploads.strikinglycdn.com/files/bd6c7257-1b1c-4f44-b554-8878fd358c88/jazizeg.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report