SUSPICIOUS — 2523509.pdf
SUSPICIOUS — 2523509.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2e1b447cc8df899d6b7c2747bccef78eae1b977ac729c8930c14057a3b28d857 - SHA-1:
0ae8848fa2f31b8b40065e8dee02c18037c28dd5 - MD5:
f6255d94d68d7e74d1c3a4814147b206 - ssdeep:
768:sgGzpDXpzM1aX1pPBZ+sD59iBwWm2QkvwCgvG2dz4MEhCCyPczuVveO63rIheo:pGFTpxb9FWm2DvNuVoCCyPczuVB60heo - TLSH:
T156318DF710A7ED0C7B8B6B03ADAB15AA658AC34C6136D7B1449C772CC4BC5BD6E00821 - Submitted as: 2523509.pdf
- File type: pdf · Size: 42641 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/4b8c0b3b-19d4-4208-a45d-6d8fd135eae4/71533622294.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=maus%20quotes%20about%20richieu, https://uploads.strikinglycdn.com/files/285eabbf-a454-4a98-862c-4b92523c6323/lifimefipuzakipid.pdf, https://uploads.strikinglycdn.com/files/4b8c0b3b-19d4-4208-a45d-6d8fd135eae4/71533622294.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=maus%20quotes%20about%20richieu
- https://uploads.strikinglycdn.com/files/285eabbf-a454-4a98-862c-4b92523c6323/lifimefipuzakipid.pdf
- https://uploads.strikinglycdn.com/files/4b8c0b3b-19d4-4208-a45d-6d8fd135eae4/71533622294.pdf
- https://uploads.strikinglycdn.com/files/eb7c3ee7-65f7-4227-8661-f242ccc02b97/12000092096.pdf
- https://uploads.strikinglycdn.com/files/6fad5a8e-ed70-44ae-b6a9-98a1b4608e42/pelefufexidax.pdf
- https://uploads.strikinglycdn.com/files/9cc69fa9-8abf-49a6-b5a2-e11b334ecd83/91654202070.pdf
- https://cdn.shopify.com/s/files/1/0499/1690/3585/files/covet_fashion_hack_reddit.pdf
- https://cdn.shopify.com/s/files/1/0500/0475/4601/files/52360076428.pdf
- https://cdn.shopify.com/s/files/1/0481/7829/9031/files/wuvijujabagoxufik.pdf
- https://site-1040780.mozfiles.com/files/1040780/rixavozajademupunasiraxi.pdf
- https://site-1041600.mozfiles.com/files/1041600/6345050223.pdf
- https://site-1041579.mozfiles.com/files/1041579/mexababezojivimef.pdf
- https://site-1043245.mozfiles.com/files/1043245/14588657325.pdf
- https://jizonuwuko.weebly.com/uploads/1/3/0/8/130814311/xapaw.pdf
- https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/636913.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/zakeme.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/3250b5961ed1.pdf
- https://dirigesibujov.weebly.com/uploads/1/3/0/9/130969991/vexuwubebupejenuv.pdf
- https://wekubuzebebam.weebly.com/uploads/1/3/0/7/130739705/vuwejij.pdf
- https://loguxofe.weebly.com/uploads/1/3/0/7/130775118/vitiregavoxofe-xaviferatavatax.pdf
- https://seririgikum.weebly.com/uploads/1/3/0/7/130739922/bamuralizoxaxetexe.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/4867245.pdf
- https://cdn-cms.f-static.net/uploads/4365613/normal_5f871e595312a.pdf
- https://cdn-cms.f-static.net/uploads/4371267/normal_5f88ef4468b62.pdf
- https://cdn-cms.f-static.net/uploads/4366630/normal_5f874bfa2e4a3.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1040780.mozfiles.com
- site-1041600.mozfiles.com
- site-1041579.mozfiles.com
- site-1043245.mozfiles.com
- jizonuwuko.weebly.com
- jaserasozupog.weebly.com
- dimaxafazeza.weebly.com
- mojivimimujovo.weebly.com
- dirigesibujov.weebly.com
- wekubuzebebam.weebly.com
- loguxofe.weebly.com
- seririgikum.weebly.com
- gimejexoxixaza.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report