SUSPICIOUS — ddf8a70db761ffa.pdf
SUSPICIOUS — ddf8a70db761ffa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a5c148e86e83fe3c6da87dea3af38c1eca667882de9edc42c53d501acdb1f8b7 - SHA-1:
c05abd677d2a50d10094332f3a5776d3661a3e7a - MD5:
8ce5a4e4b14e973be359f1c4e4806016 - ssdeep:
1536:vGFRpDhiLYqMX5HmohH8kQN8cESW1fAVA:eFRptiMDtFhckG8cEJiA - TLSH:
T1FE347DF3D097DDBC76869F03756A10796D8A864821E597B0098876EFF87C2AC6F00970 - Submitted as: ddf8a70db761ffa.pdf
- File type: pdf · Size: 55859 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://lowizozexide.weebly.com/uploads/1/3/0/7/130776176/4008283.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=practical%20unit%20testing%20with%20testng%20a, https://xumabilere.weebly.com/uploads/1/3/1/1/131163638/277641.pdf, https://naxesitigas.weebly.com/uploads/1/3/0/7/130740165/0555cef4e0.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=practical%20unit%20testing%20with%20testng%20a
- https://xumabilere.weebly.com/uploads/1/3/1/1/131163638/277641.pdf
- https://naxesitigas.weebly.com/uploads/1/3/0/7/130740165/0555cef4e0.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/5145133.pdf
- https://lowizozexide.weebly.com/uploads/1/3/0/7/130776176/4008283.pdf
- https://uploads.strikinglycdn.com/files/f7ae0f79-24af-41a4-9d22-1f1fd4ae2392/navoxuxi.pdf
- https://cdn-cms.f-static.net/uploads/4369138/normal_5f8b124425691.pdf
- https://cdn-cms.f-static.net/uploads/4365586/normal_5f8767a0d380f.pdf
- https://cdn-cms.f-static.net/uploads/4367313/normal_5f893bd28a005.pdf
- https://cdn-cms.f-static.net/uploads/4366347/normal_5f88bb883b8f4.pdf
- https://uploads.strikinglycdn.com/files/a78b949a-e888-4cd2-a1c8-8faad5bb5673/18653838105.pdf
- https://uploads.strikinglycdn.com/files/16669bf6-4305-4ebe-95b0-af573af4e93c/82216333864.pdf
- https://uploads.strikinglycdn.com/files/848ee6b3-385a-4688-82c3-05385780f9b6/vopiwituwapesarajipof.pdf
- https://uploads.strikinglycdn.com/files/a8bb6148-978c-4d23-a036-722154913138/11192845450.pdf
- https://uploads.strikinglycdn.com/files/b6930e89-6a7e-4e79-ab32-382eaba1613c/nidotelakup.pdf
- https://cdn.shopify.com/s/files/1/0437/2715/9448/files/choices_game_hack_without_human_verification.pdf
- https://cdn.shopify.com/s/files/1/0440/7777/7061/files/55394951812.pdf
- https://cdn.shopify.com/s/files/1/0479/5226/5379/files/90821329675.pdf
- https://cdn.shopify.com/s/files/1/0497/5070/4298/files/geometry_circle_equations_worksheets.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- xumabilere.weebly.com
- naxesitigas.weebly.com
- wepugimi.weebly.com
- lowizozexide.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report