SUSPICIOUS — 70cda7d16cabdc.pdf
SUSPICIOUS — 70cda7d16cabdc.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
331a41ded90b07b1cdb2ae8d1ec27a20a5d8a6c909bfa1fff5000ab526629737 - SHA-1:
3a33bad6fcb9a7154f42c27233d938a0841ccd86 - MD5:
05ca915e69d1113bc69e1e5d3a938860 - ssdeep:
1536:uGFjejRQjhsgtVtvLtuRzX2kbFraROWfB5wvo5:XFje+VsgtYRzX2CFrsfGC - TLSH:
T14B358DF72097DD8C7A8B6B439CEB1295658EC7C87223979054886A2CC5BC6BD7F10C60 - Submitted as: 70cda7d16cabdc.pdf
- File type: pdf · Size: 60936 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/503844b4-13fa-43b4-9180-7112062e4e3f/rovamuruzaridu.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=marie%20lu%20legend%20pdf, https://uploads.strikinglycdn.com/files/a7da6329-ac13-4f4d-afd4-f8fdbec818d6/likizogi.pdf, https://uploads.strikinglycdn.com/files/503844b4-13fa-43b4-9180-7112062e4e3f/rovamuruzaridu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=marie%20lu%20legend%20pdf
- https://uploads.strikinglycdn.com/files/a7da6329-ac13-4f4d-afd4-f8fdbec818d6/likizogi.pdf
- https://uploads.strikinglycdn.com/files/503844b4-13fa-43b4-9180-7112062e4e3f/rovamuruzaridu.pdf
- https://uploads.strikinglycdn.com/files/ca915cd7-5016-4d72-9eb7-83d0b56be7df/51207859245.pdf
- https://uploads.strikinglycdn.com/files/a6e399af-aa6b-419e-8b07-bd0a45e2eb9d/nonawaguwavubamurutif.pdf
- https://uploads.strikinglycdn.com/files/685c8872-599d-4613-80f6-f0e77de152fb/35223858224.pdf
- https://uploads.strikinglycdn.com/files/da05ea36-4f48-4015-8146-a1158c810760/manebimomapugerawore.pdf
- https://uploads.strikinglycdn.com/files/408e6ee6-c9ed-4dac-90b0-254c2d82b997/goronon.pdf
- https://uploads.strikinglycdn.com/files/335b6d98-6c11-4238-ae37-90063906a1d4/woreratovupafib.pdf
- https://uploads.strikinglycdn.com/files/1c5cd60b-bce6-4cef-a278-85c60ac38350/tizaxojefidetofu.pdf
- https://uploads.strikinglycdn.com/files/628ecf3a-3628-4dde-8137-d55c942063dd/66195690123.pdf
- https://site-1042988.mozfiles.com/files/1042988/zoxozeme.pdf
- https://site-1042824.mozfiles.com/files/1042824/install_whatsapp_on_my_android_tablet.pdf
- https://site-1037856.mozfiles.com/files/1037856/vupumodixeke.pdf
- https://site-1044146.mozfiles.com/files/1044146/xumamevowexosokimal.pdf
- https://site-1043761.mozfiles.com/files/1043761/rosobazafet.pdf
- https://cdn-cms.f-static.net/uploads/4366057/normal_5f876c5bc559a.pdf
- https://cdn-cms.f-static.net/uploads/4365624/normal_5f876036432a6.pdf
- https://cdn-cms.f-static.net/uploads/4367633/normal_5f876213ea485.pdf
- https://cdn-cms.f-static.net/uploads/4366359/normal_5f8778dc21264.pdf
- https://cdn-cms.f-static.net/uploads/4366982/normal_5f8774a2789f7.pdf
- https://cdn-cms.f-static.net/uploads/4367308/normal_5f876e977bfb3.pdf
- https://cdn-cms.f-static.net/uploads/4368747/normal_5f8787f18fce6.pdf
- https://cdn-cms.f-static.net/uploads/4366306/normal_5f870f33cb755.pdf
- https://cdn-cms.f-static.net/uploads/4368221/normal_5f877c25eb31a.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1042988.mozfiles.com
- site-1042824.mozfiles.com
- site-1037856.mozfiles.com
- site-1044146.mozfiles.com
- site-1043761.mozfiles.com
- cdn-cms.f-static.net
- dosedupuwosiwoz.weebly.com
- ruwopevod.weebly.com
- jatorogerujew.weebly.com
- zuxuzesis.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report