SUSPICIOUS — d8b2972f413225.pdf
SUSPICIOUS — d8b2972f413225.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9a428b23f3e4d1cfe87688f59729dfb08ddb7b3ff8c12b00ced574dfb16c867c - SHA-1:
8621c3161f3b0f85ab87629c3a5f5b85e6930036 - MD5:
e4f0e0068faf9ff415dd6c4708d97350 - ssdeep:
1536:jGFipSqEaJlbreMQHObCZyr//x+0Nyp5HW/4t2O:yFipSdU/eqZTxRNyrWAt - TLSH:
T19034B0F30093ED8CBA8A6B079EEB25891048D78D7277976445C83B2ED4BC5ADBD50860 - Submitted as: d8b2972f413225.pdf
- File type: pdf · Size: 55421 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/ea076e84-b4df-41a8-8f32-ee43fb170192/43333205680.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=captive%20curse%20walkthrough, https://site-1039998.mozfiles.com/files/1039998/ridutaramukotixenoge.pdf, https://site-1038575.mozfiles.com/files/1038575/7635520257.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=captive%20curse%20walkthrough
- https://site-1039998.mozfiles.com/files/1039998/ridutaramukotixenoge.pdf
- https://site-1038575.mozfiles.com/files/1038575/7635520257.pdf
- https://site-1037212.mozfiles.com/files/1037212/bejid.pdf
- https://site-1040346.mozfiles.com/files/1040346/90432623899.pdf
- https://uploads.strikinglycdn.com/files/ea076e84-b4df-41a8-8f32-ee43fb170192/43333205680.pdf
- https://uploads.strikinglycdn.com/files/9b3eeb29-1836-4cd1-b9ae-13abdf5153ad/53290228333.pdf
- https://uploads.strikinglycdn.com/files/5a9def16-1683-4662-8a54-a4c7e3ef319d/zefejodisuke.pdf
- https://cdn.shopify.com/s/files/1/0483/4207/3507/files/human_anatomy__physiology_10th_edition.pdf
- https://cdn.shopify.com/s/files/1/0431/9477/7757/files/jilusanofa.pdf
- https://cdn.shopify.com/s/files/1/0481/7764/3687/files/coloring_dna_answer_key.pdf
- https://uploads.strikinglycdn.com/files/81b3c6a9-63c6-4d59-be35-dd160069bd36/xaravezifaxuw.pdf
- https://uploads.strikinglycdn.com/files/048cfd8c-0f4b-4f46-8cf4-fc061cb3ea84/78337388007.pdf
- https://cdn.shopify.com/s/files/1/0435/6341/7759/files/1799224837.pdf
- https://cdn.shopify.com/s/files/1/0482/2240/4760/files/hey_black_child_poem_poster.pdf
- https://uploads.strikinglycdn.com/files/5332ddba-bbdf-461c-88c8-bcc36b27a66d/sitirimuxoweketum.pdf
- https://uploads.strikinglycdn.com/files/d618de9d-c67d-47d1-a40b-3fe6c593bcef/32209967929.pdf
- https://uploads.strikinglycdn.com/files/4353a6a8-1fa6-4907-a31c-9eaba67a27f4/kubanobowixowijenud.pdf
- https://uploads.strikinglycdn.com/files/c02f8ae1-62a6-42c6-b693-0ff05450dcda/9659390829.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1039998.mozfiles.com
- site-1038575.mozfiles.com
- site-1037212.mozfiles.com
- site-1040346.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report