SUSPICIOUS — 2967354.pdf
SUSPICIOUS — 2967354.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
10025d1ff85ee1b22aaf4ac7e85613d85301ca7af45b6c290f765ff392d0191b - SHA-1:
99c1515139ae854cc045c34d8a2a680447171208 - MD5:
6da015b3862f59c5376d1030aaa6b175 - ssdeep:
12288:L0XA92tNL9XdjI/bw1Qo1K6HhpAWek+Evzox:Ll92rhdM/E1hFhp3ek10x - TLSH:
T1264A12FBD2AADD9DB7869FA36DDA1150648DC30941216B8024887F0CA9FC33D7E22741 - Submitted as: 2967354.pdf
- File type: pdf · Size: 434511 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/650161f0-e21d-4075-8aa4-3c7b85ba94e9/fabevulokinilulo.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=cambridge%20english%20empower%20a2%20pdf, https://uploads.strikinglycdn.com/files/2b54182e-2114-4288-bde7-adc9d58a5a15/65034706547.pdf, https://uploads.strikinglycdn.com/files/ade6d25c-d871-4557-ba7a-b65c061283f5/76722458324.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=cambridge%20english%20empower%20a2%20pdf
- https://uploads.strikinglycdn.com/files/2b54182e-2114-4288-bde7-adc9d58a5a15/65034706547.pdf
- https://uploads.strikinglycdn.com/files/ade6d25c-d871-4557-ba7a-b65c061283f5/76722458324.pdf
- https://uploads.strikinglycdn.com/files/2a81a84b-4ce5-4abd-b28f-1fb5d6cfe04e/44833064334.pdf
- https://uploads.strikinglycdn.com/files/650161f0-e21d-4075-8aa4-3c7b85ba94e9/fabevulokinilulo.pdf
- https://uploads.strikinglycdn.com/files/f3e2ebf9-3e13-4924-8030-1a547ca30a5b/labud.pdf
- https://site-1038772.mozfiles.com/files/1038772/8038125366.pdf
- https://site-1039420.mozfiles.com/files/1039420/xakupot.pdf
- https://site-1040800.mozfiles.com/files/1040800/89510705846.pdf
- https://site-1037211.mozfiles.com/files/1037211/raxojowopofusesemubakax.pdf
- https://cdn.shopify.com/s/files/1/0485/0250/5633/files/images_of_angels.pdf
- https://cdn.shopify.com/s/files/1/0437/8155/4325/files/98708249281.pdf
- https://cdn.shopify.com/s/files/1/0494/1047/4151/files/864850964.pdf
- https://site-1036969.mozfiles.com/files/1036969/50185368039.pdf
- https://site-1038738.mozfiles.com/files/1038738/zozopokezuvabazajob.pdf
- https://site-1043203.mozfiles.com/files/1043203/72896813317.pdf
- https://site-1040898.mozfiles.com/files/1040898/12884557439.pdf
- https://site-1041845.mozfiles.com/files/1041845/99698976629.pdf
- https://damijuvik.weebly.com/uploads/1/3/1/3/131381376/riluxijozepeba-levimepumob-lokepaxan-depufa.pdf
- https://viweposedijul.weebly.com/uploads/1/3/1/0/131070314/9376504.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/lemebakagur.pdf
- https://fupexorugukemig.weebly.com/uploads/1/3/0/8/130814763/cb248828b.pdf
- https://cdn.shopify.com/s/files/1/0498/2915/0882/files/tusatabat.pdf
- https://cdn.shopify.com/s/files/1/0437/2509/5062/files/87183364968.pdf
- https://cdn.shopify.com/s/files/1/0501/8127/5808/files/tuzotasopokevivuwasiture.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1038772.mozfiles.com
- site-1039420.mozfiles.com
- site-1040800.mozfiles.com
- site-1037211.mozfiles.com
- cdn.shopify.com
- site-1036969.mozfiles.com
- site-1038738.mozfiles.com
- site-1043203.mozfiles.com
- site-1040898.mozfiles.com
- site-1041845.mozfiles.com
- damijuvik.weebly.com
- viweposedijul.weebly.com
- boguvetasitob.weebly.com
- fupexorugukemig.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report