SUSPICIOUS — 6988776.pdf
SUSPICIOUS — 6988776.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
723f486bb57a9c47ca279e0c983e3c137e87f1f774b4bd95ea860e0e18611080 - SHA-1:
d9b4d19a9d008b9dfb37ddd733a6349362dc9131 - MD5:
3b8f1123f7746022c0256ce74325b7c0 - ssdeep:
768:0gGzpDf5neHvxVwB8cBtYgliQxIkYcsHk8XxXXFn0mQAGFffdihTptlg:BGFD5oqd0YIkxsHk8JXy+MdMTptlg - TLSH:
T16B327EF350A7EE4C768B5F83AEB711999189C38C31369790458C7B2CC5BCAAD2F01A51 - Submitted as: 6988776.pdf
- File type: pdf · Size: 46235 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/041f3209-64d7-451c-9045-25c6d4e6358e/glimmerglass_book.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=calcul%20du%20fond%20de%20roulement%20%C3%A0%20partir%20du%20bilan%20pdf, https://cdn.shopify.com/s/files/1/0432/8967/3883/files/56434613511.pdf, https://cdn.shopify.com/s/files/1/0428/4655/2227/files/diwur.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=calcul%20du%20fond%20de%20roulement%20%C3%A0%20partir%20du%20bilan%20pdf
- https://s3.amazonaws.com/kitakilesa/10325626313.pdf
- https://s3.amazonaws.com/vososasoxumete/10271704138.pdf
- https://s3.amazonaws.com/bejeseja/sojonezibonudijezol.pdf
- https://s3.amazonaws.com/xukonakefules/etiologia_del_cancer.pdf
- https://s3.amazonaws.com/wilugugo/university_recommendation_letter_sample.pdf
- https://cdn.shopify.com/s/files/1/0432/8967/3883/files/56434613511.pdf
- https://cdn.shopify.com/s/files/1/0428/4655/2227/files/diwur.pdf
- https://cdn.shopify.com/s/files/1/0484/4319/5542/files/dungeon_quest_hack_android_1.pdf
- https://cdn.shopify.com/s/files/1/0498/1057/1419/files/geocomposite_wall_drain.pdf
- https://uploads.strikinglycdn.com/files/be864cd7-0724-432d-9839-210c34058811/bopenofejateligurelizoxem.pdf
- https://uploads.strikinglycdn.com/files/041f3209-64d7-451c-9045-25c6d4e6358e/glimmerglass_book.pdf
- https://uploads.strikinglycdn.com/files/de781638-7732-46c3-8537-7dcbe0bdf941/exercicios_de_concordancia_verbal.pdf
- https://uploads.strikinglycdn.com/files/41573ae0-53bb-46f4-8294-b7add9782adf/motojawuxenovevalisa.pdf
- https://uploads.strikinglycdn.com/files/416bf4c4-725a-41c6-b758-7e76eef799e5/65320105857.pdf
- https://uploads.strikinglycdn.com/files/13c72602-db1d-4578-a651-9967dc300cb4/seronupufonoli.pdf
- https://uploads.strikinglycdn.com/files/37253d37-1868-4e4b-bf2d-c2a6838e749a/633592509.pdf
- https://uploads.strikinglycdn.com/files/cf30c2a0-3e62-4034-88ad-005ea730deef/navimezobesut.pdf
- https://cdn.shopify.com/s/files/1/0434/2779/1009/files/fomuwukaviv.pdf
- https://cdn.shopify.com/s/files/1/0268/7696/9157/files/aji_dulce_peppers_near_me.pdf
- https://cdn.shopify.com/s/files/1/0496/1049/0022/files/57792954085.pdf
- https://uploads.strikinglycdn.com/files/9f0d5f67-987a-4b38-960f-ebe474f2ebc3/keruramijanikotexolowi.pdf
- https://uploads.strikinglycdn.com/files/d1c09636-9e1d-43f7-9ba4-13b2d814f6d5/jumitolezilewopuwirudevub.pdf
- https://uploads.strikinglycdn.com/files/b6f60102-4c5e-4c55-bde3-9b87a648b338/rogurajokorizejozedof.pdf
- https://uploads.strikinglycdn.com/files/d881e7f8-74e7-4c5e-a6eb-ed0a635efb3d/62300576143.pdf
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report