SUSPICIOUS — 3167106f5.pdf
SUSPICIOUS — 3167106f5.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
985dea2c78e52f597793583b8a3f33b4e7a58b7bc9c959b553b8a10bf7a78c5a - SHA-1:
34a772ef480f84ea78d92dea61f8f37ef462f5c1 - MD5:
c9afc01f0ca85fdeea275e9cbe6d3fd8 - ssdeep:
768:+gGzpDPpYdnB5EpVNoQqCIq8RoYDuGH3jPeA+biHkMdi0ThRUmxLdnHKzc8rUMHg:7GFrpYdHqAOFKZTU+dHP86WjUh - TLSH:
T11A328CF39097EC8C3E8B9717A9A71659548EE38C6127D75014CCAA2CD07C5BDBE108A0 - Submitted as: 3167106f5.pdf
- File type: pdf · Size: 46526 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/81196e13-889d-4392-8df4-c8be64126346/80809455021.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=alpha%20boiler%20manual, https://uploads.strikinglycdn.com/files/81196e13-889d-4392-8df4-c8be64126346/80809455021.pdf, https://uploads.strikinglycdn.com/files/417139f3-02ca-4b13-87ca-d122a09efc78/pizusowexupaxom.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=alpha%20boiler%20manual
- https://uploads.strikinglycdn.com/files/81196e13-889d-4392-8df4-c8be64126346/80809455021.pdf
- https://uploads.strikinglycdn.com/files/417139f3-02ca-4b13-87ca-d122a09efc78/pizusowexupaxom.pdf
- https://uploads.strikinglycdn.com/files/f1449394-6da9-41eb-be8e-25a6a1e8b292/dodukovafowegepewob.pdf
- https://uploads.strikinglycdn.com/files/775625cf-2f59-4849-ae2e-2cec9efd7b4d/gaxagijokudimekoj.pdf
- https://cdn-cms.f-static.net/uploads/4368979/normal_5f879cc93b7f3.pdf
- https://cdn-cms.f-static.net/uploads/4366341/normal_5f872469eb7ec.pdf
- https://cdn-cms.f-static.net/uploads/4369173/normal_5f87a1b9ef46a.pdf
- https://cdn-cms.f-static.net/uploads/4366341/normal_5f8721a2022c5.pdf
- https://cdn-cms.f-static.net/uploads/4365563/normal_5f8716a55cf1c.pdf
- https://cdn.shopify.com/s/files/1/0433/4351/1706/files/vic_darchinyan_net_worth.pdf
- https://cdn.shopify.com/s/files/1/0484/0777/3336/files/lead_free_dishes_at_walmart.pdf
- https://cdn.shopify.com/s/files/1/0481/2102/0569/files/samsung_nx58m9420ss_installation_manual.pdf
- https://cdn.shopify.com/s/files/1/0431/3638/5181/files/wolf_trap_seating_chart.pdf
- https://cdn.shopify.com/s/files/1/0479/6629/0076/files/behaviorism_and_social_learning_theory_overemphasize.pdf
- https://uploads.strikinglycdn.com/files/8bc9c436-901d-486b-8dfa-def602bf50e4/jininupewogevetodi.pdf
- https://uploads.strikinglycdn.com/files/460a3dab-889c-4876-997e-bf1371e81e56/82146275303.pdf
- https://uploads.strikinglycdn.com/files/16f11be0-739b-4a85-9bbf-8bf525e3054d/47615052099.pdf
- https://uploads.strikinglycdn.com/files/279c00ef-69a2-4be7-84c1-91100ecfced8/64172168120.pdf
- https://cdn-cms.f-static.net/uploads/4366040/normal_5f877ee02cec9.pdf
- https://cdn-cms.f-static.net/uploads/4366048/normal_5f87b6d08a906.pdf
- https://cdn-cms.f-static.net/uploads/4368238/normal_5f87788c74448.pdf
- https://cdn-cms.f-static.net/uploads/4366028/normal_5f86f9d3ba735.pdf
- https://cdn-cms.f-static.net/uploads/4366022/normal_5f87aa08aa43b.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report