SUSPICIOUS — 5144297.pdf
SUSPICIOUS — 5144297.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c0790f6d10dd5989b2d0b4f71e0bce96c0107902f8964e261a5822dbe982c10c - SHA-1:
80d65a5d743f85381c3a4da954fb3375f7d955df - MD5:
35adf048fe2fe02bcf5c1e4a44480a42 - ssdeep:
768:YgGzpDEZ5BhLus4DQdSZWMVXJollNOHlqnzKNfXA30Vqta1ElxXJosx:1GFwZxSQAZWM5JollgHlGh30stUElxZZ - TLSH:
T1C633CFF3605BDD8CBA4AEB076EFA04993449D64DA13297B01CD97A3DC4B82FC6E10520 - Submitted as: 5144297.pdf
- File type: pdf · Size: 48338 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/d12842d9-5e87-4044-8641-689bdad10f26/tepozedulukiru.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=ax15%20transmission%20rebuild%20manual, https://uploads.strikinglycdn.com/files/dbf1d895-56ea-4e5f-a0eb-53339d5a985f/29270211461.pdf, https://uploads.strikinglycdn.com/files/492a6c56-ae77-4679-9606-d103f4810ae2/tamil_serial_today_247_vinayagar.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=ax15%20transmission%20rebuild%20manual
- https://uploads.strikinglycdn.com/files/dbf1d895-56ea-4e5f-a0eb-53339d5a985f/29270211461.pdf
- https://uploads.strikinglycdn.com/files/492a6c56-ae77-4679-9606-d103f4810ae2/tamil_serial_today_247_vinayagar.pdf
- https://cdn-cms.f-static.net/uploads/4444866/normal_5f9dceaddd4aa.pdf
- https://uploads.strikinglycdn.com/files/2bad6323-bd60-480b-99d0-1433b9d5f47a/41254497659.pdf
- https://s3.amazonaws.com/bezegoluzose/pdf_file_to_jpg_converter_free.pdf
- https://uploads.strikinglycdn.com/files/102ffe62-27aa-45c1-873a-4194d95a8f17/69668195729.pdf
- https://s3.amazonaws.com/wujodibu/tanda_dan_gejala_bronkitis_kronis.pdf
- https://uploads.strikinglycdn.com/files/88749c20-7997-4ae2-8791-607472f97be8/38470509926.pdf
- https://s3.amazonaws.com/tosevud/rarojebunitojukirerexa.pdf
- https://uploads.strikinglycdn.com/files/d12842d9-5e87-4044-8641-689bdad10f26/tepozedulukiru.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- s:\bf
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report