SUSPICIOUS — 4b93ffefac3.pdf
SUSPICIOUS — 4b93ffefac3.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f3b3d4b4a7517957c9e28835b9459a68aecfcdae3c164ea5418ddf7f95ffce18 - SHA-1:
669c50802a0938c45d826f357a628e257f2cc975 - MD5:
a50d27403d689518e9ac7fb1a3a039cc - ssdeep:
1536:JGFdOeVq2NqIW6YWuE/Lqfo90zuStDcF:cFdJ02dRpuE/GfNJtW - TLSH:
T12833AEF350ABED9C3E876F17E8B615482149D6886137A7A048DA3A6CC4BC1FC3F41865 - Submitted as: 4b93ffefac3.pdf
- File type: pdf · Size: 51801 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/db870d04-73a2-4f44-8eb4-9c01f0c007e7/dikiboxo.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://traffmen.ru/wb?keyword=visions%20federal%20credit%20union%20binghamton, https://uploads.strikinglycdn.com/files/db870d04-73a2-4f44-8eb4-9c01f0c007e7/dikiboxo.pdf, https://cdn-cms.f-static.net/uploads/4365624/normal_5f871a1a00bce.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffmen.ru/wb?keyword=visions%20federal%20credit%20union%20binghamton
- https://uploads.strikinglycdn.com/files/db870d04-73a2-4f44-8eb4-9c01f0c007e7/dikiboxo.pdf
- https://s3.amazonaws.com/dukajevo/6421106042.pdf
- https://cdn-cms.f-static.net/uploads/4365624/normal_5f871a1a00bce.pdf
- https://cdn-cms.f-static.net/uploads/4410002/normal_5f95fa20bf489.pdf
- https://cdn-cms.f-static.net/uploads/4445534/normal_5fa70357688aa.pdf
- https://uploads.strikinglycdn.com/files/44c83ca9-365d-478e-a38a-b590734a43a0/structure_et_transformation_de_la_matire.pdf
- https://bakuwosir.weebly.com/uploads/1/3/0/8/130874569/1dba87367b978c.pdf
- https://xedexebil.weebly.com/uploads/1/3/4/2/134235570/jenuzapofuparosow.pdf
- https://jatilesaza.weebly.com/uploads/1/3/4/3/134316516/kumosozis.pdf
- https://cdn-cms.f-static.net/uploads/4445557/normal_5f9e67f8d2c17.pdf
- https://s3.amazonaws.com/subud/44410580547.pdf
- https://repemigikaji.weebly.com/uploads/1/3/4/6/134608024/tixawugopejige.pdf
- https://cdn-cms.f-static.net/uploads/4382618/normal_5f9cd07deb557.pdf
- https://safikevobajegev.weebly.com/uploads/1/3/4/3/134352312/15391f.pdf
- https://cdn-cms.f-static.net/uploads/4378155/normal_5f8ee4f382ed4.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffmen.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- bakuwosir.weebly.com
- xedexebil.weebly.com
- jatilesaza.weebly.com
- repemigikaji.weebly.com
- safikevobajegev.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report