SUSPICIOUS — 8580768.pdf
SUSPICIOUS — 8580768.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
31ffad65e3d3a3b4bf51bea2e0e6e7d06b1f1ceb9067eb259b3c737cede0132d - SHA-1:
33e1660944dc3c530e63440f48075e257252daee - MD5:
40de4e7ac104393a9150edac2d2ed5c5 - ssdeep:
1536:TGF2py+jTkCs44qOOWi/cFm6sbSIDqTzptQR:iF2p644zOWiemtbSIuJQ - TLSH:
T12335AEF39097ED4C7A8B9B036AE7159D908AE7883133A790448C772DC5BC7AE2E50521 - Submitted as: 8580768.pdf
- File type: pdf · Size: 58170 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/bdd95c1d-efe1-427c-a5d9-dd0b6efec0e6/81313226095.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=steam%20cycle%20in%20thermal%20power%20plant%20pdf, https://uploads.strikinglycdn.com/files/bdd95c1d-efe1-427c-a5d9-dd0b6efec0e6/81313226095.pdf, https://uploads.strikinglycdn.com/files/6c744ce0-e5fe-44ae-85fe-ae1a1d52369b/can_t_stop_praising_his_name_chords.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=steam%20cycle%20in%20thermal%20power%20plant%20pdf
- https://uploads.strikinglycdn.com/files/bdd95c1d-efe1-427c-a5d9-dd0b6efec0e6/81313226095.pdf
- https://uploads.strikinglycdn.com/files/6c744ce0-e5fe-44ae-85fe-ae1a1d52369b/can_t_stop_praising_his_name_chords.pdf
- https://uploads.strikinglycdn.com/files/da41f69c-a9d8-4858-8282-564092554b50/72364486726.pdf
- https://s3.amazonaws.com/sugaguxagu/ncfm_technical_analysis_book.pdf
- https://s3.amazonaws.com/tetazino/blood_relation_questions.pdf
- https://s3.amazonaws.com/felasorarabipis/13946151058.pdf
- https://s3.amazonaws.com/fonazuzixagizir/integral_calculus_drive.pdf
- https://s3.amazonaws.com/gupawupigawono/color_street_application.pdf
- https://cdn.shopify.com/s/files/1/0434/7189/6741/files/einfach_schreiben_a1.pdf
- https://cdn.shopify.com/s/files/1/0503/0019/0917/files/furious_8_drag_racing_mod_apk_android.pdf
- https://cdn.shopify.com/s/files/1/0266/8445/7146/files/zuvap.pdf
- https://cdn.shopify.com/s/files/1/0505/4015/0981/files/jiwefemutop.pdf
- https://cdn.shopify.com/s/files/1/0268/7582/2278/files/32991589827.pdf
- https://uploads.strikinglycdn.com/files/d4624aac-ddc9-4a63-964a-4b57e0a5ac89/99441770357.pdf
- https://uploads.strikinglycdn.com/files/87cc7bfb-d7ac-4e14-b468-89cd01afd5f4/fallout_4_nuka_world_power_plant.pdf
- https://uploads.strikinglycdn.com/files/9ae2f3ca-dd06-49be-8fa3-bcb42a38c0fb/41895080136.pdf
- https://uploads.strikinglycdn.com/files/1913e612-b9e9-43c9-a8af-b213ad5f0917/iso_14122-2.pdf
- https://uploads.strikinglycdn.com/files/480c71cf-4dab-477d-873c-0987224d6e50/26014410372.pdf
- https://uploads.strikinglycdn.com/files/937bbee3-da98-4d8b-b3d5-1eb2858a86ed/97646431344.pdf
- https://uploads.strikinglycdn.com/files/8d83356b-9caa-4b2e-b2ca-7de79fd80746/kashmiri_dictionary.pdf
- https://cdn-cms.f-static.net/uploads/4366343/normal_5f87c8847b433.pdf
- https://cdn-cms.f-static.net/uploads/4385876/normal_5f8f680cddf11.pdf
- https://cdn-cms.f-static.net/uploads/4368494/normal_5f8c92d5bbd1f.pdf
- https://cdn-cms.f-static.net/uploads/4376088/normal_5f8ff7adbb893.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report