SUSPICIOUS — 4507959.pdf
SUSPICIOUS — 4507959.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ca8b09f5d47420c65bfbcecb61b8515b9f1ba4c7f4551c218b1dc8d5f9c3dc9d - SHA-1:
d265cbdb9775895230cf1795f252daec192eb964 - MD5:
7f6b2bc657c6af4731f36767634e274e - ssdeep:
768:pgGzpDipMYtEj595ebFAzdqA+mebmQIfK2ilqIBveQAQZ:KGF2p+oNmQ4hExBveQAQZ - TLSH:
T19A328CF314EBED4CB98A9B03ADAB25191189C74DA072D6A0904C772CD5BC6FDBE50920 - Submitted as: 4507959.pdf
- File type: pdf · Size: 43761 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/e03f7231-4516-44b6-8b14-02290052173a/kopubiviwaki.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=wwe%20raw%20flash%20game, https://uploads.strikinglycdn.com/files/e03f7231-4516-44b6-8b14-02290052173a/kopubiviwaki.pdf, https://uploads.strikinglycdn.com/files/74625830-4f3c-41e8-8f53-762cf4f5754b/49524875502.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=wwe%20raw%20flash%20game
- https://uploads.strikinglycdn.com/files/e03f7231-4516-44b6-8b14-02290052173a/kopubiviwaki.pdf
- https://uploads.strikinglycdn.com/files/74625830-4f3c-41e8-8f53-762cf4f5754b/49524875502.pdf
- https://uploads.strikinglycdn.com/files/3108cb34-6f93-4440-90c8-8d5cb9a2325e/ziwafosetadavuwo.pdf
- https://uploads.strikinglycdn.com/files/72ab9cba-aa31-4c6f-bab5-a754d1030fe8/veveditinimegamudunitoj.pdf
- https://cdn.shopify.com/s/files/1/0484/2956/4062/files/jizetipudowizasopeba.pdf
- https://cdn.shopify.com/s/files/1/0461/8197/4169/files/72904193138.pdf
- https://cdn.shopify.com/s/files/1/0437/9541/5189/files/5e_shield_of_faith_stack.pdf
- https://cdn.shopify.com/s/files/1/0431/3923/5997/files/48443215618.pdf
- https://cdn-cms.f-static.net/uploads/4370264/normal_5f88aa17f2d41.pdf
- https://cdn-cms.f-static.net/uploads/4366005/normal_5f86f44d77986.pdf
- https://site-1043246.mozfiles.com/files/1043246/32286162214.pdf
- https://site-1040388.mozfiles.com/files/1040388/1720791440.pdf
- https://site-1039745.mozfiles.com/files/1039745/37608168553.pdf
- https://site-1041579.mozfiles.com/files/1041579/30868374264.pdf
- https://uploads.strikinglycdn.com/files/d233ac15-6271-4147-9df8-5f46727ace57/42313678682.pdf
- https://uploads.strikinglycdn.com/files/abc51ac0-180e-46b9-9002-d626e41e0d90/doborobiwazivutusunaxe.pdf
- https://uploads.strikinglycdn.com/files/ee898c19-aba7-4466-9633-927ac49fa00f/45581118059.pdf
- https://site-1038979.mozfiles.com/files/1038979/sopafedotipejanurazeturud.pdf
- https://site-1036644.mozfiles.com/files/1036644/modosixewegederogomid.pdf
- https://site-1039874.mozfiles.com/files/1039874/11312964387.pdf
- https://site-1036781.mozfiles.com/files/1036781/87791727472.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1043246.mozfiles.com
- site-1040388.mozfiles.com
- site-1039745.mozfiles.com
- site-1041579.mozfiles.com
- site-1038979.mozfiles.com
- site-1036644.mozfiles.com
- site-1039874.mozfiles.com
- site-1036781.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report