SUSPICIOUS — 42a56da7a08.pdf
SUSPICIOUS — 42a56da7a08.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d910940abf5b7659709a23cb7c21a51483cbc7fe13da503cc21c2205360900e9 - SHA-1:
b34bd3e41d6caba432f0c9bd66c7a7eda8c4cc69 - MD5:
2835bc21823f0762ba65cd2a647c637f - ssdeep:
768:igGzpDjpXAT3B+g7ANmoJLQJiYwn3pWn/EYg1QmKq:/GFvpX0cNj+iL5W/En1QmKq - TLSH:
T10F317DF350A7DC4CBB8AAB036D7A1895518AC38C6237AB6044D8776CC5BC6BDBD10870 - Submitted as: 42a56da7a08.pdf
- File type: pdf · Size: 41609 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/aba3f424-85ea-45d7-9340-389ba4f0fd99/24655902798.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=vitamina%20b2%20bula%20pdf, https://uploads.strikinglycdn.com/files/aba3f424-85ea-45d7-9340-389ba4f0fd99/24655902798.pdf, https://uploads.strikinglycdn.com/files/97ace31e-afa7-415a-831e-7beacd2a9d60/fewuza.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=vitamina%20b2%20bula%20pdf
- https://uploads.strikinglycdn.com/files/aba3f424-85ea-45d7-9340-389ba4f0fd99/24655902798.pdf
- https://uploads.strikinglycdn.com/files/97ace31e-afa7-415a-831e-7beacd2a9d60/fewuza.pdf
- https://uploads.strikinglycdn.com/files/29cc7ad2-c4e8-434c-8db8-fdfadcf9cd83/4497175376.pdf
- https://uploads.strikinglycdn.com/files/a5a628bf-91da-4a2b-99a3-6ceab919cb7d/85518488845.pdf
- https://uploads.strikinglycdn.com/files/d7fc1c7f-907b-41fd-b6a5-5b505fd61a0a/dafol.pdf
- https://s3.amazonaws.com/wovitiku/sekotonuviluvarojuron.pdf
- https://s3.amazonaws.com/panalipolifod/aide_to_dwg_converter_online.pdf
- https://s3.amazonaws.com/susopuzupure/human_anatomy_internal_organs.pdf
- https://s3.amazonaws.com/dugibabafod/zelda_breath_of_the_wild_walkthrough_book.pdf
- https://s3.amazonaws.com/fosagobomap/bohr_magneton.pdf
- https://s3.amazonaws.com/sikuva/self_esteem_bible.pdf
- https://s3.amazonaws.com/fujadabez/pemiruwefusowozinevida.pdf
- https://s3.amazonaws.com/wonoti/lulexotumivorukisiduxo.pdf
- https://uploads.strikinglycdn.com/files/d59b3cbd-bb38-45ad-a016-8da07987a2d7/foxekirejog.pdf
- https://uploads.strikinglycdn.com/files/add52dc4-6845-451c-8e10-19ae4c643baa/77687381967.pdf
- https://uploads.strikinglycdn.com/files/5eb3587a-75c0-4613-80e3-404e4c996727/david_mcgraw_30_day_challenge.pdf
- https://uploads.strikinglycdn.com/files/3d94bff4-fbd7-407b-9c8f-650cec3cae85/download_taken_2.pdf
- https://uploads.strikinglycdn.com/files/5564d168-7f7b-45c5-8743-2a3af281629c/dubagubavubarugofupura.pdf
- https://uploads.strikinglycdn.com/files/d6b5ccb2-bea8-4630-8727-516e8833eee0/27166570144.pdf
- https://uploads.strikinglycdn.com/files/90b0538f-43a8-4d57-833c-0605d0fc3b83/kedif.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report