SUSPICIOUS — b2a3c84c9f5.pdf
SUSPICIOUS — b2a3c84c9f5.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
62d8f85ae930aa6447818ce16da053298f1e60ecc286e0149009f9ed2c284ef8 - SHA-1:
905868256831ddc96d760e90f2ad660a7d0f0b77 - MD5:
d62222e333fbced6c3e4f3cdcbab5bad - ssdeep:
768:ogGzpD3x9RgYTayTzdq8bbaek2MFLPqCGazxiwPE4WWFeKU6:lGFjhTJq8bbhk3FLPqNavB9FeKU6 - TLSH:
T176309DF340ABDD8C6A87AB83A8E715A5A54AC3897133927108DC766DC47C2FD7F40861 - Submitted as: b2a3c84c9f5.pdf
- File type: pdf · Size: 38094 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/b18c3a6b-cc21-4c23-8152-c72526f4d4db/gawebibobon.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=mk2%20golf%20haynes%20manual%20pdf, https://uploads.strikinglycdn.com/files/b18c3a6b-cc21-4c23-8152-c72526f4d4db/gawebibobon.pdf, https://uploads.strikinglycdn.com/files/66963a8c-ccf6-4532-976a-f9336573f756/20194725797.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=mk2%20golf%20haynes%20manual%20pdf
- https://uploads.strikinglycdn.com/files/b18c3a6b-cc21-4c23-8152-c72526f4d4db/gawebibobon.pdf
- https://uploads.strikinglycdn.com/files/66963a8c-ccf6-4532-976a-f9336573f756/20194725797.pdf
- https://uploads.strikinglycdn.com/files/56cb096d-2d1f-44b7-8db3-7e2cfbad0723/advanced_word_family_lists.pdf
- https://cdn.shopify.com/s/files/1/0497/6669/5071/files/harvard_business_school_case.pdf
- https://uploads.strikinglycdn.com/files/875160ef-f21d-41ed-b4c2-7d57acf7f5ca/fundamento_de_pcr.pdf
- https://uploads.strikinglycdn.com/files/ad2e43bd-5e3d-4016-ac1b-6bd021a1f9d3/81969392895.pdf
- https://uploads.strikinglycdn.com/files/97aa08bf-b595-4175-82c0-53342b9e4f84/ice_fishing_games_unblocked.pdf
- https://cdn.shopify.com/s/files/1/0462/4479/0426/files/85966949894.pdf
- https://uploads.strikinglycdn.com/files/51ae03ef-65ff-4e2a-96ae-d7a6238ec017/lenovo_yoga_c930_review.pdf
- https://cdn-cms.f-static.net/uploads/4366306/normal_5f877f7d26000.pdf
- https://cdn.shopify.com/s/files/1/0496/4096/4252/files/hill_climb_racing_hack_download_apkpure.pdf
- https://uploads.strikinglycdn.com/files/1a303e6d-7111-46b1-bf03-3729146f5760/60043595256.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report