SUSPICIOUS — 6669402.pdf
SUSPICIOUS — 6669402.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ddfe9782bb65d431a7bbbf37632dac78b56c5097ab9ea0b97be0055711478b22 - SHA-1:
72f666660d9ba6fc309d36bca2428e8c783ceb48 - MD5:
74639bbe13a68828be434f4e2416f61b - ssdeep:
768:jgGzpDzmQaidGXwBRDy279pfrexiuoK/hAnr2/5ahVRlDA19NFmtwiG3ng:cGFHjBI27zeUt0SiwdteXsMng - TLSH:
T16532AFF75197DCCC7ACBAF1769E51068654AC28C65325AB008C93B7CC8BC7ACBE50861 - Submitted as: 6669402.pdf
- File type: pdf · Size: 47441 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/ebd39225-e98c-454f-95a5-f24c8a3f2d48/17846937969.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=weight%20watchers%20points%20plus%20books, https://uploads.strikinglycdn.com/files/ebd39225-e98c-454f-95a5-f24c8a3f2d48/17846937969.pdf, https://cdn-cms.f-static.net/uploads/4383450/normal_5f914c8717e1d.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=weight%20watchers%20points%20plus%20books
- https://uploads.strikinglycdn.com/files/ebd39225-e98c-454f-95a5-f24c8a3f2d48/17846937969.pdf
- https://cdn-cms.f-static.net/uploads/4383450/normal_5f914c8717e1d.pdf
- https://cdn-cms.f-static.net/uploads/4415045/normal_5f9905160e77d.pdf
- https://cdn-cms.f-static.net/uploads/4387711/normal_5f8eb366a8599.pdf
- https://jiwepurojal.weebly.com/uploads/1/3/0/7/130775762/c4888d02c.pdf
- https://cdn-cms.f-static.net/uploads/4447646/normal_5f9ec77912f0b.pdf
- https://uploads.strikinglycdn.com/files/9c590703-a768-4b8a-8b2a-293bc45316cc/gooseberry_pie_recipe_with_tapioca.pdf
- https://s3.amazonaws.com/susopuzupure/toraxofonavexajalokubine.pdf
- https://uploads.strikinglycdn.com/files/12de95fb-855d-46b3-af85-998a37d05a8b/travaille_fin_de_degr_uco.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- jiwepurojal.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report