SUSPICIOUS — gesanowizowa.pdf
SUSPICIOUS — gesanowizowa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
28d61d61a8cc40f481fb88b45aedd151abb3d00ab813a29a361b3ac6e2677848 - SHA-1:
58318d4bed8370926dac915949f8d887c150a8f1 - MD5:
e05887f3ad2d48dacb05625c132c9d35 - ssdeep:
768:LlgGzpD+YH97Akw9nuMV8zkJF0zu5G37EcTH693hcft0IqxNWOj8Y2IFi:qGFy74k0C5zPph3Iqxj8YBi - TLSH:
T176319EF310A7EC8C3A8AAB036EBB115D518AC6897177D76018CC663DD1B85FD6F10A21 - Submitted as: gesanowizowa.pdf
- File type: pdf · Size: 42653 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://widajufi.depthstiny.com/uploads/1/3/0/8/130814579/jajuvabegojenoj.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=wayne+battery+backup+sump+pump+manual, http://files.coveyoupottery.com/uploads/1/3/1/3/131384142/9f2a2fbb.pdf, http://files.redonesmarketing.com/uploads/1/3/0/8/130814014/duvapig_pejar.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=wayne+battery+backup+sump+pump+manual
- http://files.coveyoupottery.com/uploads/1/3/1/3/131384142/9f2a2fbb.pdf
- http://files.redonesmarketing.com/uploads/1/3/0/8/130814014/duvapig_pejar.pdf
- http://widajufi.depthstiny.com/uploads/1/3/0/8/130814579/jajuvabegojenoj.pdf
- http://genen.freebirdok.com/uploads/1/3/2/6/132681396/wasamux.pdf
- http://files.iqjointventureholdings.net/uploads/1/3/1/3/131382092/5087052.pdf
- https://uploads.strikinglycdn.com/files/6149f7a3-6170-4bd3-9ab5-8d64b6f25119/59202509888.pdf
- https://uploads.strikinglycdn.com/files/d649048b-28f3-4963-94f3-ec21f88f6862/32691220146.pdf
- https://uploads.strikinglycdn.com/files/9764f2ec-ff84-4a22-ad91-4a91ce6efc4f/6065190595.pdf
- https://uploads.strikinglycdn.com/files/cbd2aca0-bda9-4d69-85f8-83e7a5f19b02/5577393718.pdf
- https://cdn.shopify.com/s/files/1/0484/5004/4069/files/subnautica_multipurpose_room_blueprint_location_2018.pdf
- https://cdn.shopify.com/s/files/1/0483/7782/3385/files/csusm_ge_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0435/0679/4651/files/quest_to_learn.pdf
- https://cdn.shopify.com/s/files/1/0428/3046/3135/files/motion_for_reconsideration_massachusetts_criminal.pdf
- https://cdn.shopify.com/s/files/1/0483/2257/6548/files/red_wolf_meat_classic_db.pdf
- https://cdn.shopify.com/s/files/1/0440/3114/8197/files/gafisogoriso.pdf
- https://cdn.shopify.com/s/files/1/0497/4755/8561/files/3964280989.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- files.coveyoupottery.com
- files.redonesmarketing.com
- widajufi.depthstiny.com
- genen.freebirdok.com
- files.iqjointventureholdings.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report