SUSPICIOUS — 64b13d7d.pdf
SUSPICIOUS — 64b13d7d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
54eba4bc68aba5f10ddf9dd782de54fb375d8165e7ea12fb5101a96899e7d02c - SHA-1:
6a4f4083f0f5bb8430bed13afab750961f9bc9cb - MD5:
3bf299723b71771cef84d016c43d59bb - ssdeep:
768:xgGzpDDV+at02C/xxf9fckCBk0aQ2leprB2vN28v3ea1sqmARR:CGF/L9k0a8aVT3zsq5RR - TLSH:
T1A3318CF75093ED4C7E879F47BDAA246C615AD2882133AA1048CCB76CC4BC6EE7D50861 - Submitted as: 64b13d7d.pdf
- File type: pdf · Size: 40296 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/db350978-9c97-4a00-93aa-2a9651b28fbb/redonofe.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=dupe%20script%20for%20lumber%20tycoon%202, https://uploads.strikinglycdn.com/files/db350978-9c97-4a00-93aa-2a9651b28fbb/redonofe.pdf, https://cdn.shopify.com/s/files/1/0499/8139/0998/files/vipomogo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=dupe%20script%20for%20lumber%20tycoon%202
- https://uploads.strikinglycdn.com/files/db350978-9c97-4a00-93aa-2a9651b28fbb/redonofe.pdf
- https://cdn.shopify.com/s/files/1/0499/8139/0998/files/vipomogo.pdf
- https://uploads.strikinglycdn.com/files/d4a92c11-0eaa-45b3-938e-7d1a76e6ba90/xilozumuvix.pdf
- https://uploads.strikinglycdn.com/files/3526e813-57f7-4d3f-8ae2-15180a79b27e/fumimaze.pdf
- https://cdn.shopify.com/s/files/1/0501/5198/1249/files/gentoo_kernel_upgrade_guide.pdf
- https://uploads.strikinglycdn.com/files/4ffb88fc-4c65-4429-9f0d-b6ec8b91b47c/18112562511.pdf
- https://cdn.shopify.com/s/files/1/0502/3055/8878/files/28199103062.pdf
- https://cdn-cms.f-static.net/uploads/4426819/normal_5f9ac6519c841.pdf
- https://cdn.shopify.com/s/files/1/0507/7414/7240/files/property_management_companies_in_long_beach.pdf
- https://uploads.strikinglycdn.com/files/8db82ef3-18e9-4559-a031-06185edc29c2/printable_multiplication_tables_from.pdf
- https://s3.amazonaws.com/fazujo/convertir_to_word_candy.pdf
- https://s3.amazonaws.com/wavunot/the_book_of_the_secrets_of_enoch.pdf
- https://s3.amazonaws.com/jowutoneranemuk/99227422216.pdf
- https://s3.amazonaws.com/wipotegadodorek/bistro_fada_chords.pdf
- https://uploads.strikinglycdn.com/files/9ae2ec9a-fd8d-45b6-a40f-276caf745c59/94506252153.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report