SUSPICIOUS — 3779580.pdf
SUSPICIOUS — 3779580.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ccfd6bc28a19d6df20773016fc49eed2cc525b5247e9d363be865a5ab28f0af8 - SHA-1:
9fd948cac37aa3993e527f5146cc7aa391dee9b8 - MD5:
b016f431ea42f2cc67bbeca125021323 - ssdeep:
768:3gGzpD0pVyKXoQqed5s3xqmW9EEu3ue6hBgTguDIK1/fBkKHEuoR:QGFYp+qhGcK5OyEuoR - TLSH:
T176318EF35063EC8D3A8A6F43ADDB1159A189C28D6067C760449C776DD0BCAFD2E40A61 - Submitted as: 3779580.pdf
- File type: pdf · Size: 42316 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/689cca43-fd44-4e07-8fde-0c9416a45d05/60043989764.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=skyrim%20invisible%20npc%20fix, https://cdn.shopify.com/s/files/1/0430/6803/1143/files/20087828837.pdf, https://cdn.shopify.com/s/files/1/0430/7487/9642/files/google_play_store_android_apps_download.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=skyrim%20invisible%20npc%20fix
- https://cdn.shopify.com/s/files/1/0430/6803/1143/files/20087828837.pdf
- https://cdn.shopify.com/s/files/1/0430/7487/9642/files/google_play_store_android_apps_download.pdf
- https://cdn.shopify.com/s/files/1/0494/0569/0023/files/faint-banded_sea_snake_bite.pdf
- https://uploads.strikinglycdn.com/files/689cca43-fd44-4e07-8fde-0c9416a45d05/60043989764.pdf
- https://uploads.strikinglycdn.com/files/50c28847-b2b8-46c4-84f9-389c1b87f577/naraxamaw.pdf
- https://site-1039313.mozfiles.com/files/1039313/lilumurubinuzovevapadol.pdf
- https://site-1037009.mozfiles.com/files/1037009/9001019575.pdf
- https://site-1043925.mozfiles.com/files/1043925/bugovojupenego.pdf
- https://uploads.strikinglycdn.com/files/fa6e4dbd-1c23-4398-9021-4fda6896372f/niruj.pdf
- https://uploads.strikinglycdn.com/files/65c5052d-cef1-4b7e-8d2e-240e2f0b46bb/wavajusurogevamutabadav.pdf
- https://uploads.strikinglycdn.com/files/831a7370-1d75-493f-8f50-fc6bf611b230/tezesexuw.pdf
- https://cdn.shopify.com/s/files/1/0435/8320/9633/files/harry_potter_thestral_tattoo.pdf
- https://cdn.shopify.com/s/files/1/0495/9112/4131/files/breast_milk_soap_benefits.pdf
- https://cdn.shopify.com/s/files/1/0431/1485/6610/files/zenonia_5_apk_free_download.pdf
- https://cdn.shopify.com/s/files/1/0492/3041/3980/files/ti_nspire_ti_84_plus_keypad_manual.pdf
- https://cdn.shopify.com/s/files/1/0479/2277/4180/files/complete_guide_to_life_drawing_bammes.pdf
- https://cdn.shopify.com/s/files/1/0482/9433/0526/files/3.4_assessment_biology_answers.pdf
- https://cdn.shopify.com/s/files/1/0430/9857/0913/files/60549997372.pdf
- https://modwat.ch/u/frostymoonlightI
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- https://modwat.ch/u/frostymoonlightI'
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1039313.mozfiles.com
- site-1037009.mozfiles.com
- site-1043925.mozfiles.com
- modwat.ch
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report