SUSPICIOUS — db97b4b.pdf
SUSPICIOUS — db97b4b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fe486cfc12fc5302c330ce15837ed95ce6baa9a325cf1d79f35f7de68e4e7f4b - SHA-1:
8d8be33a182e634f3436afdcfd982af6099588b9 - MD5:
0e18947b1ecbe5cec2289cc76b6e24c2 - ssdeep:
768:SgGzpD1p+KvovGt+M5n2oHFdK+72s7a7jwrpvVi7vvnhE0FosG5O+wdUB81P1:PGFBp+tqJej8mvhPOs5+wdUB81P1 - TLSH:
T14A329EF35197EC4CBA8A9B43AEE610EE9488D64DA132D360458C772CD17C6FE7E00961 - Submitted as: db97b4b.pdf
- File type: pdf · Size: 43644 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/0abb7025-c2c5-4344-afe3-76e21dcab297/80521395264.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=descaling%20a%20keurig%20with%20vinegar, https://uploads.strikinglycdn.com/files/0abb7025-c2c5-4344-afe3-76e21dcab297/80521395264.pdf, https://uploads.strikinglycdn.com/files/73639305-8d54-4ac5-9ad8-2fdcb636635c/92305269571.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=descaling%20a%20keurig%20with%20vinegar
- https://uploads.strikinglycdn.com/files/0abb7025-c2c5-4344-afe3-76e21dcab297/80521395264.pdf
- https://uploads.strikinglycdn.com/files/73639305-8d54-4ac5-9ad8-2fdcb636635c/92305269571.pdf
- https://uploads.strikinglycdn.com/files/b7c00929-bfdf-4c96-ad9d-4ac72a9c60e5/35674688016.pdf
- https://uploads.strikinglycdn.com/files/3acf693b-1192-4e90-b636-471353552956/57564428374.pdf
- https://uploads.strikinglycdn.com/files/cb74b92f-4a45-40f3-a5c6-5329f0ffa7d2/17744918885.pdf
- https://roninuvanajeg.weebly.com/uploads/1/3/1/3/131379749/domujofurebaxis.pdf
- https://cdn.shopify.com/s/files/1/0428/8361/2831/files/72332331362.pdf
- https://cdn.shopify.com/s/files/1/0467/5387/4083/files/fomubojurizutasonotuxe.pdf
- https://cdn.shopify.com/s/files/1/0437/9148/3032/files/linear_relationship_definition_science.pdf
- https://cdn.shopify.com/s/files/1/0435/3723/6119/files/celula_procariota_y_eucariota.pdf
- https://cdn.shopify.com/s/files/1/0496/9368/7965/files/figures_of_architecture_and_thought.pdf
- https://site-1038538.mozfiles.com/files/1038538/ferazew.pdf
- https://site-1039733.mozfiles.com/files/1039733/rejabis.pdf
- https://site-1037849.mozfiles.com/files/1037849/45012774976.pdf
- https://site-1039948.mozfiles.com/files/1039948/demand_management_techniques.pdf
- https://cdn.shopify.com/s/files/1/0499/1028/4456/files/jufisu.pdf
- https://cdn.shopify.com/s/files/1/0496/0685/2759/files/mulevubivodunijakogimet.pdf
- https://cdn.shopify.com/s/files/1/0433/1490/5256/files/98419483905.pdf
- https://cdn.shopify.com/s/files/1/0499/8873/1042/files/guvarobotiniwadixijuwirot.pdf
- https://cdn.shopify.com/s/files/1/0502/3943/9032/files/avengers_theme_piano.pdf
- https://cdn.shopify.com/s/files/1/0440/3062/3894/files/pelev.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- roninuvanajeg.weebly.com
- cdn.shopify.com
- site-1038538.mozfiles.com
- site-1039733.mozfiles.com
- site-1037849.mozfiles.com
- site-1039948.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report