SUSPICIOUS — f78be.pdf
SUSPICIOUS — f78be.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5ed42ca99757334d2decb5a1554fafd34b078a27bee9a3d6b64c4e3b2562db59 - SHA-1:
9eb0ebf4f2bb26bfe2f9deb249c4878372096b18 - MD5:
755de6bd46cd2cc874d96a3ad84a7955 - ssdeep:
768:ngGzpDpppl5X5CCgKo22ditzkFCYzGyx8CEw8cEvN+uM9IBYRI+:gGFFppl5MN8YzGBCx8Xv0tIBYRI+ - TLSH:
T1EF328DF360D3EC8C7A8FAB03AEE601586145D7846136A36054DCB32DD5BCAFD6E10A64 - Submitted as: f78be.pdf
- File type: pdf · Size: 44586 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/df390aa6-5e2a-49ed-af53-e847b9f93284/didapupomiduzasejeg.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=verizon%20jetpack%20unlimited%20data, https://cdn.shopify.com/s/files/1/0501/7757/3054/files/focus_group_interviews.pdf, https://cdn.shopify.com/s/files/1/0493/1108/8799/files/5_gallon_bucket_seat.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=verizon%20jetpack%20unlimited%20data
- https://cdn.shopify.com/s/files/1/0501/7757/3054/files/focus_group_interviews.pdf
- https://cdn.shopify.com/s/files/1/0493/1108/8799/files/5_gallon_bucket_seat.pdf
- https://cdn.shopify.com/s/files/1/0266/8501/4213/files/gixezetidegitosagebavi.pdf
- https://uploads.strikinglycdn.com/files/2bd8db7d-3f50-47a3-b942-c92ce0660d7f/lewamowopiteb.pdf
- https://runebipunozup.weebly.com/uploads/1/3/1/4/131406604/jajopikalo_lusov.pdf
- https://tedomidile.weebly.com/uploads/1/3/2/7/132712102/pazufososegaruvoko.pdf
- https://uploads.strikinglycdn.com/files/df390aa6-5e2a-49ed-af53-e847b9f93284/didapupomiduzasejeg.pdf
- https://uploads.strikinglycdn.com/files/79b1dfb3-8470-401c-ba9c-6c6a0606eba6/84916491394.pdf
- https://uploads.strikinglycdn.com/files/f958a6bd-009b-4e9c-8a8f-954a1b1513dd/diferencias_entre_fabulas_y_refranes.pdf
- https://uploads.strikinglycdn.com/files/6800e41a-2b8c-43db-8fed-80d53e9b41c2/22183894191.pdf
- https://uploads.strikinglycdn.com/files/6c94f486-a575-46ef-98cb-f293efd3b2f8/41121087475.pdf
- https://uploads.strikinglycdn.com/files/5cbd3354-ad59-4587-b605-cb41ac9a1c78/12260546923.pdf
- https://cdn-cms.f-static.net/uploads/4368468/normal_5f877c17ca50e.pdf
- https://cdn-cms.f-static.net/uploads/4366642/normal_5f87423fb10bc.pdf
- https://cdn-cms.f-static.net/uploads/4366388/normal_5f871d37dd776.pdf
- https://cdn-cms.f-static.net/uploads/4366627/normal_5f8758745935f.pdf
- https://cdn-cms.f-static.net/uploads/4370074/normal_5f895b398f413.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- runebipunozup.weebly.com
- tedomidile.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report