SUSPICIOUS — relazi.pdf
SUSPICIOUS — relazi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2a93324af1866a0b37d65abfc7e63764f4e9eae726fbf0f1f37e9b0e0c631b3a - SHA-1:
1270c8961f64d94f830e31efbbc0edef7b657d4b - MD5:
c725f8497a7def7e0a9e56eaf796073a - ssdeep:
768:cgGzpD7CTyfxS8EE+k/IFR1zw1UCVgBsykOnzeyKdm8yaD9gnX6Z6:5GF3N/yEnVM/zOk8yaD2qZ6 - TLSH:
T15931BFFBA087DDCC6AC95B077FA214696549CBCC713386A410C8776C84FC2BEAE00691 - Submitted as: relazi.pdf
- File type: pdf · Size: 41172 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/39ff8703-5b9f-4c02-9ce7-89cbf9b6e572/75420329857.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://trafficel.ru/wb?keyword=unblocked%20minecraft%20152, https://nopirirog.weebly.com/uploads/1/3/4/2/134234714/91a5717a1bf4e32.pdf, https://cdn-cms.f-static.net/uploads/4374859/normal_5f89ecafb4682.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafficel.ru/wb?keyword=unblocked%20minecraft%20152
- https://nopirirog.weebly.com/uploads/1/3/4/2/134234714/91a5717a1bf4e32.pdf
- https://dukugasamu.files.wordpress.com/2020/11/loc_multi_purpose_cleaner.pdf
- https://cdn-cms.f-static.net/uploads/4374859/normal_5f89ecafb4682.pdf
- https://ranerenonosojib.weebly.com/uploads/1/3/1/4/131483420/5269681.pdf
- https://uploads.strikinglycdn.com/files/39ff8703-5b9f-4c02-9ce7-89cbf9b6e572/75420329857.pdf
- https://uploads.strikinglycdn.com/files/119751a0-9e49-433d-bd3a-d2a7578ff19e/63229025578.pdf
- https://cdn-cms.f-static.net/uploads/4413570/normal_5f9e78875f64f.pdf
- https://cdn-cms.f-static.net/uploads/4378383/normal_5f95579a2ffd5.pdf
- https://cdn-cms.f-static.net/uploads/4375083/normal_5f9c71c5b77a6.pdf
- https://uploads.strikinglycdn.com/files/9af1bedc-0a94-4a7a-bd37-52a59e0b49fa/robapofi.pdf
- https://uploads.strikinglycdn.com/files/35a9cc94-3331-41b5-8b24-fb8c3f20ffe6/72216993186.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafficel.ru
- nopirirog.weebly.com
- dukugasamu.files.wordpress.com
- cdn-cms.f-static.net
- ranerenonosojib.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report