SUSPICIOUS — 439013.pdf
SUSPICIOUS — 439013.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3f58ec436c08057aff698e53fff682bc011162c996b3752ddfabe7a0d4f20d53 - SHA-1:
d021d9578d8d0d83c1b45d396f839a0b8b65b10c - MD5:
161f4f1f06fb5ce3efae3e3382062f13 - ssdeep:
1536:WGFGpruCmURocRQJUiSZn4qJd8sQdrv1JD:vFGpxXTREUiSZ9Jd8sQdrf - TLSH:
T1E935CFF36093EC5CBA86EB939CE618687199E3C83526D7A0448C667E807C7BD7F10461 - Submitted as: 439013.pdf
- File type: pdf · Size: 58636 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/49e8cfc3-d1d0-45c2-a607-13480ad820ea/559998690.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=gigabyte%20z370%20aorus%20ultra%20gaming%20mot, https://uploads.strikinglycdn.com/files/49e8cfc3-d1d0-45c2-a607-13480ad820ea/559998690.pdf, https://uploads.strikinglycdn.com/files/25754bd7-0c52-49c6-b158-864f519bafe1/xatisize.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=gigabyte%20z370%20aorus%20ultra%20gaming%20mot
- https://uploads.strikinglycdn.com/files/49e8cfc3-d1d0-45c2-a607-13480ad820ea/559998690.pdf
- https://uploads.strikinglycdn.com/files/25754bd7-0c52-49c6-b158-864f519bafe1/xatisize.pdf
- https://uploads.strikinglycdn.com/files/0c966f9e-f14e-4314-818f-8f90b80948ac/pumomopora.pdf
- https://uploads.strikinglycdn.com/files/f8e3cf03-ba4e-4582-8fe0-6302825224ac/buxakanojoguroporusipalov.pdf
- https://putojedenavaxo.weebly.com/uploads/1/3/2/6/132683165/3121800.pdf
- https://cdn-cms.f-static.net/uploads/4366371/normal_5f8aeebd1fb48.pdf
- https://cdn-cms.f-static.net/uploads/4381318/normal_5f8d01d4c65aa.pdf
- https://cdn-cms.f-static.net/uploads/4369632/normal_5f8a4d08659ab.pdf
- https://cdn.shopify.com/s/files/1/0496/2287/6324/files/el_cerrito_recycling_center_open.pdf
- https://cdn.shopify.com/s/files/1/0486/4789/7256/files/10742025793.pdf
- https://cdn.shopify.com/s/files/1/0480/5659/8692/files/23393572157.pdf
- https://uploads.strikinglycdn.com/files/dd285de2-5db5-4e7f-8294-f773c1cc9aba/63430046148.pdf
- https://uploads.strikinglycdn.com/files/321122fb-412d-4d51-9f53-f0389efcbf29/43845320477.pdf
- https://uploads.strikinglycdn.com/files/606ff588-3fa5-458b-9ce3-29e58bb89cdf/memogemubuvuruvov.pdf
- https://uploads.strikinglycdn.com/files/a9cb6e55-c2df-42c9-b3aa-b4ffebe41d38/24286425075.pdf
- https://uploads.strikinglycdn.com/files/17cb9066-c8e5-42ce-be68-de953aedab33/32703341736.pdf
- https://uploads.strikinglycdn.com/files/92ca085a-7149-4f68-a515-f64e20044b7f/wasipukubifamum.pdf
- https://uploads.strikinglycdn.com/files/5783277e-20d0-4b97-8060-db86a01c27fe/fundamentals_of_power_electronics_2nd_edition.pdf
- https://uploads.strikinglycdn.com/files/f57b935a-9b4f-470a-a3cd-92ef35316b76/melamut.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- putojedenavaxo.weebly.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report