SUSPICIOUS — d585eab8343c0.pdf
SUSPICIOUS — d585eab8343c0.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
85742bb02045fd04972f153c02084bfa8c5735926a29161c20a578fbe9258a9d - SHA-1:
cfe4dda376231aff560d8f2e207efb0306650f78 - MD5:
fd5a7d107d58bd22c8f9f870e8d707ee - ssdeep:
1536:YGFueN9TiD7VUFAd9gCgn9mT1XZHLagXXjq:1FueN9TWWWrgCg9A1XZHLaAG - TLSH:
T14B37CFF350E7DECC7A8EAF07ADA61099A14AC248613287544488772CD4BC6FD7F01E65 - Submitted as: d585eab8343c0.pdf
- File type: pdf · Size: 69830 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/ee7924b3-9cdf-4e7a-bbc2-b864f1e195b3/zenanonozuzoxiwinawa.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=ruby%20knight%20vindicator%20build, https://site-1040032.mozfiles.com/files/1040032/dinefujij.pdf, https://site-1038519.mozfiles.com/files/1038519/wamoxuzelorezinan.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=ruby%20knight%20vindicator%20build
- https://site-1040032.mozfiles.com/files/1040032/dinefujij.pdf
- https://site-1038519.mozfiles.com/files/1038519/wamoxuzelorezinan.pdf
- https://site-1038835.mozfiles.com/files/1038835/2091733117.pdf
- https://site-1039959.mozfiles.com/files/1039959/28083466954.pdf
- https://site-1038506.mozfiles.com/files/1038506/duferoxasonironowe.pdf
- https://uploads.strikinglycdn.com/files/ee7924b3-9cdf-4e7a-bbc2-b864f1e195b3/zenanonozuzoxiwinawa.pdf
- https://uploads.strikinglycdn.com/files/a94fd26d-18a6-45b6-b263-a4dc144d6f14/rusapinen.pdf
- https://uploads.strikinglycdn.com/files/a078b509-4cfe-4d05-9df8-6dd4db7a722b/38290497087.pdf
- https://uploads.strikinglycdn.com/files/e331f352-fb81-47ef-b68f-60308ea1d68b/garibodujozoteduzepavuj.pdf
- https://uploads.strikinglycdn.com/files/f741dfe2-5f6a-423d-aa07-b191f67ab706/26724172754.pdf
- https://uploads.strikinglycdn.com/files/4348213f-b284-43fe-9aac-0e8d91e07e69/pekovudetop.pdf
- https://uploads.strikinglycdn.com/files/8895ef5a-cb3e-4e75-9302-dac6010e0896/58035452526.pdf
- https://uploads.strikinglycdn.com/files/7078dbfc-6c1b-4394-8762-6535064f37d3/feroxifo.pdf
- https://uploads.strikinglycdn.com/files/4928b6cc-b96b-4496-9be9-6027ff74afa4/nedatunen.pdf
- https://uploads.strikinglycdn.com/files/41273563-d990-4d33-aea1-baccac04890d/54145366053.pdf
- https://site-1043332.mozfiles.com/files/1043332/voraxegogufiwul.pdf
- https://site-1040317.mozfiles.com/files/1040317/13006477491.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/6431815.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/xizaxamuxive.pdf
- https://fekudumubaf.weebly.com/uploads/1/3/2/6/132681201/zinoxovij.pdf
- https://povutepumik.weebly.com/uploads/1/3/2/7/132741486/4b201c87d.pdf
- https://uploads.strikinglycdn.com/files/904f6d88-34c6-49d2-95d1-461f3f5e87fb/sororilutovapupizonupos.pdf
- https://uploads.strikinglycdn.com/files/033d6d06-ffd7-4a9d-9da1-56febe46e5cc/1395465769.pdf
- https://uploads.strikinglycdn.com/files/aa8d0924-1eb9-43c1-9367-9ba774320226/sifafumugip.pdf
Embedded domains
- ggtraff.ru
- site-1040032.mozfiles.com
- site-1038519.mozfiles.com
- site-1038835.mozfiles.com
- site-1039959.mozfiles.com
- site-1038506.mozfiles.com
- uploads.strikinglycdn.com
- site-1043332.mozfiles.com
- site-1040317.mozfiles.com
- jakedekokobara.weebly.com
- dutitujazekap.weebly.com
- fekudumubaf.weebly.com
- povutepumik.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- P:\T&h
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report