SUSPICIOUS — 5cf8a37297a.pdf
SUSPICIOUS — 5cf8a37297a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b851ae3264c81ce9c25d30b03dbc3f41dfa2698f2def1296eb2a7bc94fc3bba6 - SHA-1:
b65300fe0a155669d6887f58d88ab86243e8c3ef - MD5:
7284745a76f8e67f95e4092535074d7c - ssdeep:
768:CgGzpDipS3RSalWVVGdTRy9EidYpnG26N/f73XB3ZW3OUZh:fGFupIlRtdGvNDx3ZW3OUZh - TLSH:
T154327CF310E7ED4C7ACBEB03ADA71059648AC78971369660558C772CC0BCABD7E10661 - Submitted as: 5cf8a37297a.pdf
- File type: pdf · Size: 44863 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/bdda3029-fba7-4320-ba4f-f8a124ab7899/llave_mecanica_png.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=suddenly%20a%20knock%20on%20the%20door%20pdf, https://cdn.shopify.com/s/files/1/0501/5198/1244/files/pogekirukilevanos.pdf, https://cdn.shopify.com/s/files/1/0437/2883/0625/files/54200912333.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=suddenly%20a%20knock%20on%20the%20door%20pdf
- https://s3.amazonaws.com/widiku/buried_child_full_play.pdf
- https://s3.amazonaws.com/zazelujeju/ias_book_download_in_hindi.pdf
- https://s3.amazonaws.com/najubu/87848634929.pdf
- https://s3.amazonaws.com/panokojol/top_ielts_speaking_tips.pdf
- https://cdn.shopify.com/s/files/1/0501/5198/1244/files/pogekirukilevanos.pdf
- https://cdn.shopify.com/s/files/1/0437/2883/0625/files/54200912333.pdf
- https://cdn.shopify.com/s/files/1/0502/9324/4077/files/dusapeniwepufoguz.pdf
- https://cdn-cms.f-static.net/uploads/4403533/normal_5f98bdc4d1297.pdf
- https://cdn-cms.f-static.net/uploads/4368481/normal_5f8b25e35ebc2.pdf
- https://cdn-cms.f-static.net/uploads/4368249/normal_5f8a88937bfa1.pdf
- https://cdn-cms.f-static.net/uploads/4379049/normal_5f8d52a035e21.pdf
- https://uploads.strikinglycdn.com/files/bdda3029-fba7-4320-ba4f-f8a124ab7899/llave_mecanica_png.pdf
- https://uploads.strikinglycdn.com/files/9ab84271-1cd7-40d3-ade7-372fc81f06e1/fisetuloxebagada.pdf
- https://uploads.strikinglycdn.com/files/81ddeacb-834a-443c-941d-eb0f4516c754/.pdf
- https://uploads.strikinglycdn.com/files/f5008659-85a1-475c-8eb6-f073536da010/difipoxixasinezozot.pdf
- https://uploads.strikinglycdn.com/files/58e78c65-cb12-4faa-b499-af148db65e99/nalitelifumorudawimedelax.pdf
- https://uploads.strikinglycdn.com/files/62e19aef-09b4-4106-90f7-d92830e60885/36309424322.pdf
- https://uploads.strikinglycdn.com/files/6dc0e29e-41c8-4ff9-b9c3-e7e84f388def/34347384075.pdf
- https://s3.amazonaws.com/zetare/javascript_full_tutorial_download.pdf
- https://s3.amazonaws.com/dusubonifu/learn_share_market_basics.pdf
- https://s3.amazonaws.com/jamokaroxoj/56819913786.pdf
- https://s3.amazonaws.com/jamokaroxoj/5610893659.pdf
- https://s3.amazonaws.com/susopuzupure/silvanus_thompson_calculus_made_easy.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- s3.amazonaws.com
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report