SUSPICIOUS — 0b9bc12d.pdf
SUSPICIOUS — 0b9bc12d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
34dcdb9e3e499a22a5cf5d8cb5e54c2ec7ef63c2048872d087a1cba450e0328b - SHA-1:
8490a995d40765a0379570aeded16451b2f1831a - MD5:
9bbb130960efb8b9492fd198c83b1a58 - ssdeep:
1536:lGF4nUzrGDa5Z0v0mpDkzrNWAvkpYT8xYr:4F4nwGDa5ZKpkg5YT8G - TLSH:
T18534BEF364A3DC4C7EC6AF87AEAB116D108AD7895173966000C8632DE53CAEDBF01560 - Submitted as: 0b9bc12d.pdf
- File type: pdf · Size: 55493 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/c36b6a08-3539-4d09-9144-3264282a25d7/14499326163.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=siringomielia%20fisioterapia%20pdf, https://uploads.strikinglycdn.com/files/c36b6a08-3539-4d09-9144-3264282a25d7/14499326163.pdf, https://cdn.shopify.com/s/files/1/0501/8127/5808/files/esc_guidelines_2020_dyslipidemia.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=siringomielia%20fisioterapia%20pdf
- https://uploads.strikinglycdn.com/files/c36b6a08-3539-4d09-9144-3264282a25d7/14499326163.pdf
- https://cdn.shopify.com/s/files/1/0501/8127/5808/files/esc_guidelines_2020_dyslipidemia.pdf
- https://uploads.strikinglycdn.com/files/84962248-4d44-4adf-9c51-8136268f132e/18401770066.pdf
- https://uploads.strikinglycdn.com/files/75bf7e7f-76ea-494b-84d0-d3d9805e6c7c/wugetuso.pdf
- https://uploads.strikinglycdn.com/files/4330f534-c60e-46f7-af9b-bd154780dfa6/earth_wind_and_fire_getaway.pdf
- https://uploads.strikinglycdn.com/files/605d54da-4adb-477c-bce6-cb90141b24d2/86242554572.pdf
- https://uploads.strikinglycdn.com/files/e46a0ec1-a3f6-4d6b-b26d-5a815911b90c/sales_tax_ontario_ca.pdf
- https://uploads.strikinglycdn.com/files/c321e779-587d-4543-8ae2-5d46ca93f4d0/gudujopenuzo.pdf
- https://uploads.strikinglycdn.com/files/cb624fbe-4cc5-4049-8661-568701cec8db/77829062452.pdf
- https://uploads.strikinglycdn.com/files/d77f438d-0c34-4650-97d9-bc9a60605cef/lutefav.pdf
- https://cdn.shopify.com/s/files/1/0266/9097/7984/files/death_before_dishonor_japanese_kanji.pdf
- https://cdn.shopify.com/s/files/1/0502/7961/2616/files/easy_pop_piano_songs.pdf
- https://cdn.shopify.com/s/files/1/0500/5764/2152/files/come_convertire_in_word_online_gratis.pdf
- https://cdn.shopify.com/s/files/1/0493/7203/7286/files/national_geographic_ng76az_telescope_manual.pdf
- https://cdn.shopify.com/s/files/1/0496/0200/3108/files/4930950021.pdf
- https://uploads.strikinglycdn.com/files/a4c813c3-2942-4167-93ae-d9f110b53ea4/61679410551.pdf
- https://uploads.strikinglycdn.com/files/051f0431-7cc1-4965-94e5-a6f70592c0c9/4_absolutes_of_aa.pdf
- https://uploads.strikinglycdn.com/files/45973df1-c09a-4b20-af4f-45a9ee6a6586/homeworld_remastered_general_failure.pdf
- https://uploads.strikinglycdn.com/files/bd97e152-d5fc-4bde-a15c-16a812cc9962/danexa.pdf
- https://uploads.strikinglycdn.com/files/ddcbd20d-7671-43a2-b83b-14de4220ba33/78416061046.pdf
- https://uploads.strikinglycdn.com/files/299c7d4a-91e9-4b68-856d-efe6b6855979/kuwonipuxadugemaf.pdf
- https://cdn.shopify.com/s/files/1/0500/4846/7094/files/chapter_13_states_of_matter_answer_key.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- b.to
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report