SUSPICIOUS — d6798610c30.pdf
SUSPICIOUS — d6798610c30.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5da203412a23e1f4d6dcf9d9c08f22e39365d658f4b6e86497744e9c80d26f03 - SHA-1:
fdfd8964a3db01ea2d9f2dea4c697354a48e2ff1 - MD5:
17c0573252f3da36c25efb0e4e7f1bbf - ssdeep:
768:hgGzpDJbpAZ6ixnwNqFYeDkIF1dnMYlo1+WcCAlAwYlTaiRpnisXT7q:SGFdbpAZfEGYeQmnCAIlpRpn5j7q - TLSH:
T197338DF350B3ED4C768BAB076EAF1259618AD34DA026D790448C772DC0BC6FE6E10A11 - Submitted as: d6798610c30.pdf
- File type: pdf · Size: 47746 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/6b296f96-0b89-4ec7-9961-96519f139b77/kalovaxipineso.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=unblocked%20games%20plazma%20burst%202, https://uploads.strikinglycdn.com/files/25584b33-1d2f-4c64-a6b5-1184386e3080/nidajafimuposuvaz.pdf, https://uploads.strikinglycdn.com/files/63a52594-5d70-4b35-b59f-4bff084ae049/84984379142.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=unblocked%20games%20plazma%20burst%202
- https://uploads.strikinglycdn.com/files/25584b33-1d2f-4c64-a6b5-1184386e3080/nidajafimuposuvaz.pdf
- https://uploads.strikinglycdn.com/files/63a52594-5d70-4b35-b59f-4bff084ae049/84984379142.pdf
- https://uploads.strikinglycdn.com/files/6b296f96-0b89-4ec7-9961-96519f139b77/kalovaxipineso.pdf
- https://uploads.strikinglycdn.com/files/7b94f1d9-0f21-4a37-a705-f5e49071607f/74589343379.pdf
- https://uploads.strikinglycdn.com/files/26412cce-818f-4d76-9f11-c5572db99c49/74196134813.pdf
- https://site-1040038.mozfiles.com/files/1040038/dobobetagajebetigazareti.pdf
- https://site-1043494.mozfiles.com/files/1043494/ximobazexaz.pdf
- https://site-1048485.mozfiles.com/files/1048485/sutelurewanu.pdf
- https://site-1043937.mozfiles.com/files/1043937/12571031561.pdf
- https://site-1041286.mozfiles.com/files/1041286/18193145536.pdf
- https://cdn.shopify.com/s/files/1/0501/7029/8523/files/tadobi.pdf
- https://cdn.shopify.com/s/files/1/0496/8215/3629/files/64535627500.pdf
- https://cdn.shopify.com/s/files/1/0496/7756/6109/files/vajugavixuv.pdf
- https://uploads.strikinglycdn.com/files/f69e3aea-cb56-4bc4-9862-95b6d032df33/davikonijosabukoxabuzomi.pdf
- https://uploads.strikinglycdn.com/files/b2816826-c61f-47a4-91da-ee53805113b1/97895788363.pdf
- https://uploads.strikinglycdn.com/files/2d567a2c-854a-42fd-91e4-c635c6942443/pajoxusavegafozumubivul.pdf
- https://cdn-cms.f-static.net/uploads/4366007/normal_5f876ecdf1b2e.pdf
- https://cdn-cms.f-static.net/uploads/4365660/normal_5f876d7d75236.pdf
- https://cdn-cms.f-static.net/uploads/4365540/normal_5f875b2a4b908.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f8717cf17f4a.pdf
- https://cdn-cms.f-static.net/uploads/4366050/normal_5f874f587c879.pdf
- https://uploads.strikinglycdn.com/files/87df690a-ef94-4adb-91dd-3fd96f499adb/79621651426.pdf
- https://uploads.strikinglycdn.com/files/63450d7f-4998-4c27-bff1-a0b25e599ad8/97955798749.pdf
- https://uploads.strikinglycdn.com/files/6eea21eb-42af-4779-a061-9851747aa185/rigobirogame.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1040038.mozfiles.com
- site-1043494.mozfiles.com
- site-1048485.mozfiles.com
- site-1043937.mozfiles.com
- site-1041286.mozfiles.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report