SUSPICIOUS — 8395351.pdf
SUSPICIOUS — 8395351.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ce76f79102aec5117eef5ce90ba23ece7538e9a13cae2e7d651a7e9557ed7476 - SHA-1:
7cf82c2835498b009da9792feb0f30ca83872c59 - MD5:
6c84820c3da8782373b9a5d067d1e496 - ssdeep:
768:7gGzpDyp7YTkIOf0TY++ExV1mGZwc+VHYXe5VEKifF4bq:EGFmpCVckwc+Nee5V5i94bq - TLSH:
T17F328DF390A7ED8D3A87AF97ADB70149644983896227976004D8BB2CC57C9FD6F00970 - Submitted as: 8395351.pdf
- File type: pdf · Size: 43473 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/b19cebd8-9da8-418a-8136-79d60896a963/92260869320.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=fam%C3%ADlia%20de%2010%20integrantes%20do, https://uploads.strikinglycdn.com/files/b19cebd8-9da8-418a-8136-79d60896a963/92260869320.pdf, https://uploads.strikinglycdn.com/files/bd3f929e-5679-43c5-967f-ebee9a355290/jidevarekadapop.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=fam%C3%ADlia%20de%2010%20integrantes%20do
- https://uploads.strikinglycdn.com/files/b19cebd8-9da8-418a-8136-79d60896a963/92260869320.pdf
- https://uploads.strikinglycdn.com/files/bd3f929e-5679-43c5-967f-ebee9a355290/jidevarekadapop.pdf
- https://uploads.strikinglycdn.com/files/a4215e2f-90b3-4ed1-bff1-636e4fb961ca/warelo.pdf
- https://cdn.shopify.com/s/files/1/0480/2812/3295/files/tafalizobipekamo.pdf
- https://cdn.shopify.com/s/files/1/0268/8394/8740/files/asus_rog_hero_vii_manual.pdf
- https://cdn.shopify.com/s/files/1/0437/4318/2999/files/wow_classic_pre_raid_bis_rogue.pdf
- https://cdn.shopify.com/s/files/1/0496/2431/8103/files/11948674717.pdf
- https://cdn.shopify.com/s/files/1/0501/6761/1542/files/jazaki.pdf
- https://cdn.shopify.com/s/files/1/0486/2407/4912/files/fe_civil_manual.pdf
- https://cdn.shopify.com/s/files/1/0462/7539/5744/files/finding_asymptotes_worksheet.pdf
- https://cdn-cms.f-static.net/uploads/4365586/normal_5f86f941d03f7.pdf
- https://cdn-cms.f-static.net/uploads/4366011/normal_5f872486ccc39.pdf
- https://cdn-cms.f-static.net/uploads/4366003/normal_5f87032d7b851.pdf
- https://uploads.strikinglycdn.com/files/0dc89717-13b3-442a-8466-4f544359d893/91302395619.pdf
- https://uploads.strikinglycdn.com/files/868a5679-329d-4bcb-9964-971ff0254a48/xuwiraneravurolab.pdf
- https://uploads.strikinglycdn.com/files/1b6045f8-4dfe-41e2-bb6e-f08be2ee08dd/53097980262.pdf
- https://uploads.strikinglycdn.com/files/d4162848-cf5c-4bce-a478-d8cd2e98933b/10269076368.pdf
- https://uploads.strikinglycdn.com/files/46fe10cf-67db-47d0-b451-bf9004bcd330/92851058256.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report