SUSPICIOUS — 28800319647.pdf
SUSPICIOUS — 28800319647.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2f3d4046260f2713ae1d36299200cc58260d78c2c4d82146697ecae169600e84 - SHA-1:
b342b055e6dbaacdad89a66028438b0f5fd091a3 - MD5:
21623021bdbea7b6c14e8e0c84bbebaa - ssdeep:
3072:hFSedIhSkcjl45mN5Azhab0SdUy+3CP4EXhUtwP0KLhyU97RKz+mx:H3GhSzjl45tzhabRvPt/Pe - TLSH:
T10E3EE1F3149BED4C66C3AB53BDE7245A240ADB4871625BA0428877ADC47C76DBF20E10 - Submitted as: 28800319647.pdf
- File type: pdf · Size: 143197 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://cdn-cms.f-static.net/uploads/4366317/normal_5f87157c120fc.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=kinh+s%25C3%25A1ch+ph%25E1%25BA%25ADt+gi%25C3%25A1o+pdf, https://site-1038932.mozfiles.com/files/1038932/xujipa.pdf, https://site-1040669.mozfiles.com/files/1040669/85079423218.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=kinh+s%25C3%25A1ch+ph%25E1%25BA%25ADt+gi%25C3%25A1o+pdf
- https://site-1038932.mozfiles.com/files/1038932/xujipa.pdf
- https://site-1040669.mozfiles.com/files/1040669/85079423218.pdf
- https://site-1043793.mozfiles.com/files/1043793/mapelaxuwax.pdf
- https://site-1043239.mozfiles.com/files/1043239/wonadunu.pdf
- https://site-1039514.mozfiles.com/files/1039514/45588982705.pdf
- https://cdn.shopify.com/s/files/1/0428/2771/0630/files/91971219423.pdf
- https://cdn.shopify.com/s/files/1/0436/1083/3058/files/wetanagonewenofusepovose.pdf
- https://cdn.shopify.com/s/files/1/0502/3563/7922/files/android_activity_transition_animation_github.pdf
- https://cdn.shopify.com/s/files/1/0480/5086/4287/files/pumada.pdf
- https://tajurasexir.weebly.com/uploads/1/3/1/6/131606020/jegojes.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/aa92d.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/bupemigimamuvap.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/nidisetati.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/jaxisi.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/pokobu-pidoror-pekirez.pdf
- https://cdn-cms.f-static.net/uploads/4366003/normal_5f870b6be8afe.pdf
- https://cdn-cms.f-static.net/uploads/4366317/normal_5f87157c120fc.pdf
- https://cdn-cms.f-static.net/uploads/4365570/normal_5f871531829a7.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f8708076f7b4.pdf
- https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/topexukiguf-nulakekez.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/d96ddb407408.pdf
- https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/devuxupujikeninaferi.pdf
- https://jeponiruwapin.weebly.com/uploads/1/3/0/7/130776483/gigufoteworakef-bezari.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- site-1038932.mozfiles.com
- site-1040669.mozfiles.com
- site-1043793.mozfiles.com
- site-1043239.mozfiles.com
- site-1039514.mozfiles.com
- cdn.shopify.com
- tajurasexir.weebly.com
- mogilifus.weebly.com
- fijojonibiw.weebly.com
- dutitujazekap.weebly.com
- mojivimimujovo.weebly.com
- zoxuzuxebexot.weebly.com
- cdn-cms.f-static.net
- nudojafobedem.weebly.com
- gimejexoxixaza.weebly.com
- fodezamu.weebly.com
- jeponiruwapin.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report