SUSPICIOUS — ed5b51af953.pdf
SUSPICIOUS — ed5b51af953.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
86a854f24171493727e47c2d3906fd714c345ba9aed2e56a8ab16869aba22c09 - SHA-1:
a39d0f18e7f2a086f91ecc1ecd2f60e865fbb70b - MD5:
b533527b0f31cc05b1ee8fe5f81f1f0b - ssdeep:
1536:/GFl+4HdgFvuZuIE4GhL77IX8Z570XTRMf:uFlvdEeoL77lETm - TLSH:
T18E35AEF360E3ED9C7A86CF079EBA255D914AC7CC202796A4489D766DC1783FC6E00960 - Submitted as: ed5b51af953.pdf
- File type: pdf · Size: 58340 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/3913124d-07f7-45ee-8842-39774d65d681/10349092571.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=tcpdf%20header%20image%20height, https://uploads.strikinglycdn.com/files/3913124d-07f7-45ee-8842-39774d65d681/10349092571.pdf, https://uploads.strikinglycdn.com/files/1242485e-481e-4df7-aba5-871e212dd9c9/55976608007.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=tcpdf%20header%20image%20height
- https://s3.amazonaws.com/subud/weroforiximebutumone.pdf
- https://uploads.strikinglycdn.com/files/3913124d-07f7-45ee-8842-39774d65d681/10349092571.pdf
- https://uploads.strikinglycdn.com/files/1242485e-481e-4df7-aba5-871e212dd9c9/55976608007.pdf
- https://s3.amazonaws.com/gifiz/bubble_sort_in_data_structure_with_example.pdf
- https://uploads.strikinglycdn.com/files/ebcc7a74-bab3-4e74-8775-176ae73b59be/palobeminibopizenobit.pdf
- https://s3.amazonaws.com/pazifetanegapu/xozoveborasidumuraxuza.pdf
- https://uploads.strikinglycdn.com/files/ebf987f1-cb18-4957-b3df-7161d6ebf3c1/kepunuwunobor.pdf
- https://s3.amazonaws.com/xenavuxa/search_a_document_for_a_word.pdf
- https://uploads.strikinglycdn.com/files/d6a69633-1538-4cd2-9408-0376435086c3/48065643054.pdf
- https://uploads.strikinglycdn.com/files/78370ec3-875b-4957-a716-2a7d2f98061d/perry_local_schools_phone_number.pdf
- https://uploads.strikinglycdn.com/files/2cdf164f-b62c-4e80-8fff-a2d903fc8cbf/dishonored_2_mission_6_black_market_code.pdf
- https://uploads.strikinglycdn.com/files/784c864f-c5be-4820-9c8b-d04dc5cd7934/89313058812.pdf
- https://s3.amazonaws.com/henghuili-files/kizezofebolorabajokofiso.pdf
- https://uploads.strikinglycdn.com/files/eb896f6f-421e-4e6f-b416-dccd0e3f69bd/kalaketanileluxojekobap.pdf
- https://cdn-cms.f-static.net/uploads/4365551/normal_5f874c2a04fe7.pdf
- https://cdn-cms.f-static.net/uploads/4388819/normal_5f8fa6c3744b7.pdf
- https://s3.amazonaws.com/rebomedug/96084518304.pdf
- https://uploads.strikinglycdn.com/files/a424e681-2fcc-4972-b71b-dce877589b5b/11908989893.pdf
- https://uploads.strikinglycdn.com/files/5e9139e6-a337-4cff-a173-31110361404b/92867255634.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report