SUSPICIOUS — 4370304.pdf
SUSPICIOUS — 4370304.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3f41b8378a7fcab38232a799b72b8bfaceefb9b0ce938065fb859ab354a685d9 - SHA-1:
e377b8fb83cff972b3f4ed027af1406e4301d6f9 - MD5:
515da8bfe87ed51af0cf3e3e2ad2b4e6 - ssdeep:
1536:8GF7eggY+txS2bTRf6+W3JTh9ha71Bxzv:ZF7eZQyTRf6l599Y71/ - TLSH:
T171339EF310A7DD8D7A8B9F439DBA1099644ED7892126E79005887B6DC8BC6FC3F00A51 - Submitted as: 4370304.pdf
- File type: pdf · Size: 52078 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/56464d60-7c3f-47fa-9bae-0712af96c0c9/gogumufegiduwonifubezi.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=normas%20de%20dibujo%20tecnico, https://uploads.strikinglycdn.com/files/56464d60-7c3f-47fa-9bae-0712af96c0c9/gogumufegiduwonifubezi.pdf, https://uploads.strikinglycdn.com/files/09567050-4275-44fd-892b-4536644a326c/gepolazub.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=normas%20de%20dibujo%20tecnico
- https://uploads.strikinglycdn.com/files/56464d60-7c3f-47fa-9bae-0712af96c0c9/gogumufegiduwonifubezi.pdf
- https://uploads.strikinglycdn.com/files/09567050-4275-44fd-892b-4536644a326c/gepolazub.pdf
- https://uploads.strikinglycdn.com/files/7d02f0ce-4a3c-4c17-a57b-90141c2f3a88/53227329124.pdf
- https://cdn-cms.f-static.net/uploads/4366007/normal_5f86fc85368cd.pdf
- https://cdn-cms.f-static.net/uploads/4367275/normal_5f88a8257907a.pdf
- https://cdn-cms.f-static.net/uploads/4365591/normal_5f871732d311f.pdf
- https://cdn-cms.f-static.net/uploads/4370066/normal_5f889de698cf3.pdf
- https://cdn-cms.f-static.net/uploads/4374980/normal_5f897b7a52319.pdf
- https://cdn-cms.f-static.net/uploads/4367271/normal_5f87438892537.pdf
- https://uploads.strikinglycdn.com/files/c38672b5-1f56-4ffb-bb0b-c10785d84fa4/sebafowibuvevum.pdf
- https://uploads.strikinglycdn.com/files/34a5d9d1-0034-456e-be9e-45e114b47b99/11624238633.pdf
- https://uploads.strikinglycdn.com/files/11b22084-2fda-4117-bad7-ae4a3b224f18/75078496068.pdf
- https://uploads.strikinglycdn.com/files/e2956294-2f15-4c67-ab17-2996e379c3b3/77263223502.pdf
- https://uploads.strikinglycdn.com/files/f68ab3da-89bc-462b-b305-ecaae4b65df6/nemam.pdf
- https://cdn.shopify.com/s/files/1/0430/7222/5442/files/alpine_ida-x305s_bluetooth_no_unit.pdf
- https://cdn.shopify.com/s/files/1/0478/4947/2159/files/71380575756.pdf
- https://cdn.shopify.com/s/files/1/0435/6639/9647/files/19957184235.pdf
- https://cdn.shopify.com/s/files/1/0497/4565/8009/files/pokemon_blue_cheats_all_starters.pdf
- https://cdn-cms.f-static.net/uploads/4367631/normal_5f889a248df65.pdf
- https://cdn-cms.f-static.net/uploads/4367960/normal_5f88305340122.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report