SUSPICIOUS — 4e5bcf.pdf
SUSPICIOUS — 4e5bcf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
28856748fcacfcaf713538ae6513ecc0efde227e2f7abbc7d6ad40e8eaba5761 - SHA-1:
e51aa886d165b8e94a8e38415ae3e307fa4c9389 - MD5:
bffc10a3c16b691561fd3398ccda498a - ssdeep:
1536:JGFKpJ8Owf+UI8FQXCN3SPo+NW2D5h7atK:cFKpKFvi2SPo+b/ - TLSH:
T1B0338EF310ABDC8D768B9B83EDB61199704DD3882123A7E0498C676C85BC1BC7F52950 - Submitted as: 4e5bcf.pdf
- File type: pdf · Size: 49884 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/5dc0731d-cf53-4557-8de5-fe9c12d40b1e/48410321902.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=do%20i%20wanna%20know%20download%20free, https://uploads.strikinglycdn.com/files/7fbcebe9-cf4b-4efb-9c20-36934ded84f8/wejuzanenote.pdf, https://uploads.strikinglycdn.com/files/fe7bd7b3-3af8-4c57-9eb2-c6acd10d48cf/gufatonabizap.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=do%20i%20wanna%20know%20download%20free
- https://uploads.strikinglycdn.com/files/7fbcebe9-cf4b-4efb-9c20-36934ded84f8/wejuzanenote.pdf
- https://uploads.strikinglycdn.com/files/fe7bd7b3-3af8-4c57-9eb2-c6acd10d48cf/gufatonabizap.pdf
- https://uploads.strikinglycdn.com/files/276b2815-f8c7-4571-9be4-e9e85ef8d4d0/dajokuxifatavusul.pdf
- https://uploads.strikinglycdn.com/files/5dc0731d-cf53-4557-8de5-fe9c12d40b1e/48410321902.pdf
- https://lipowuripipu.weebly.com/uploads/1/3/1/3/131378852/dce22b3ddeb7.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/93049f265a0000.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/dekefomivupe-kovak-talajonipa-fedebiraroz.pdf
- https://cdn.shopify.com/s/files/1/0428/6224/8095/files/the_tragedy_of_great_power_politics.pdf
- https://cdn.shopify.com/s/files/1/0484/9254/4162/files/dujisikitud.pdf
- https://cdn.shopify.com/s/files/1/0479/0258/9094/files/70270281543.pdf
- https://site-1039481.mozfiles.com/files/1039481/jogubidevibitifoxixag.pdf
- https://site-1038975.mozfiles.com/files/1038975/rupugejunuvumilawubapepu.pdf
- https://site-1036872.mozfiles.com/files/1036872/mitumiremovejafe.pdf
- https://site-1039915.mozfiles.com/files/1039915/fepini.pdf
- https://site-1039544.mozfiles.com/files/1039544/69515769485.pdf
- https://cdn-cms.f-static.net/uploads/4369794/normal_5f8826e2a9f37.pdf
- https://cdn-cms.f-static.net/uploads/4366033/normal_5f884827a6304.pdf
- https://cdn-cms.f-static.net/uploads/4371013/normal_5f8846f1672bf.pdf
- https://cdn-cms.f-static.net/uploads/4366402/normal_5f8732a2d367d.pdf
- https://cdn-cms.f-static.net/uploads/4365545/normal_5f871766f159a.pdf
- https://cdn-cms.f-static.net/uploads/4366034/normal_5f875e85e3f00.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- lipowuripipu.weebly.com
- zoxuzuxebexot.weebly.com
- cdn.shopify.com
- site-1039481.mozfiles.com
- site-1038975.mozfiles.com
- site-1036872.mozfiles.com
- site-1039915.mozfiles.com
- site-1039544.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report