SUSPICIOUS — ce8784c.pdf
SUSPICIOUS — ce8784c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7385c1bf58d5e9004f01a20ce7580432af2e2375346c677e397399d92657c59d - SHA-1:
749e661cc5a54f1e20a54686189d1ef9c7ceab78 - MD5:
e053661a2dd9efbdbdd936ac7792b944 - ssdeep:
768:VgGzpDqpNJFf/0OJ9eQmB3Ok2VdbDlSyqT8O8uaGtmkJtJgy7:GGFmpf62/SgTuaRkJtJgy7 - TLSH:
T132327CF300E7ED4CBA879743ACAB11D9914AC34D7176DBA4448C6B1DC4785AEBF409A0 - Submitted as: ce8784c.pdf
- File type: pdf · Size: 47066 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/33605d48-1bcb-40a2-8db9-8c1e359e5597/ximogomafemaloze.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=watson-glaser%20critical%20thinking%20appr, https://uploads.strikinglycdn.com/files/33605d48-1bcb-40a2-8db9-8c1e359e5597/ximogomafemaloze.pdf, https://uploads.strikinglycdn.com/files/2bfadc20-061c-4b79-a5f8-9be9b8c3015b/komoroduj.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=watson-glaser%20critical%20thinking%20appr
- https://uploads.strikinglycdn.com/files/33605d48-1bcb-40a2-8db9-8c1e359e5597/ximogomafemaloze.pdf
- https://uploads.strikinglycdn.com/files/2bfadc20-061c-4b79-a5f8-9be9b8c3015b/komoroduj.pdf
- https://uploads.strikinglycdn.com/files/ad0e6109-75aa-437e-9c60-4017af35d7f4/kixura.pdf
- https://uploads.strikinglycdn.com/files/4e9e2e29-b546-40fa-8cdd-e4cba7d3d77f/pavubekizajomapet.pdf
- https://uploads.strikinglycdn.com/files/202d1502-b31c-4f70-9235-26f63066f338/3175774625.pdf
- https://site-1039509.mozfiles.com/files/1039509/silex.pdf
- https://site-1039424.mozfiles.com/files/1039424/jikovinurenir.pdf
- https://site-1039577.mozfiles.com/files/1039577/43011160671.pdf
- https://site-1037260.mozfiles.com/files/1037260/80337573099.pdf
- https://cdn-cms.f-static.net/uploads/4365624/normal_5f87a51c3814d.pdf
- https://cdn-cms.f-static.net/uploads/4365601/normal_5f87047c1f671.pdf
- https://cdn-cms.f-static.net/uploads/4365555/normal_5f86f9ad0911d.pdf
- https://cdn-cms.f-static.net/uploads/4367277/normal_5f87ac4f12839.pdf
- https://cdn.shopify.com/s/files/1/0266/9087/9682/files/16501376786.pdf
- https://cdn.shopify.com/s/files/1/0437/8332/3806/files/turtles_all_the_way_down_reddit.pdf
- https://cdn.shopify.com/s/files/1/0431/9235/2928/files/big_ass_redhead.pdf
- https://cdn.shopify.com/s/files/1/0431/1583/9645/files/sig_sauer_p226_cleaning_manual.pdf
- https://cdn.shopify.com/s/files/1/0498/8426/6654/files/komikinusijebudur.pdf
- https://jabiratunibi.weebly.com/uploads/1/3/2/6/132683422/37b650d5f73.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/40ddfa4d7f4e3e.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/vunud.pdf
- https://jemiwuwavaza.weebly.com/uploads/1/3/0/8/130814288/tigosorivibisakoxu.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/roriturosiw.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/6949257.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1039509.mozfiles.com
- site-1039424.mozfiles.com
- site-1039577.mozfiles.com
- site-1037260.mozfiles.com
- cdn-cms.f-static.net
- cdn.shopify.com
- jabiratunibi.weebly.com
- mogilifus.weebly.com
- vuxozajuje.weebly.com
- jemiwuwavaza.weebly.com
- gimejexoxixaza.weebly.com
- vozunutav.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report