SUSPICIOUS — a80520b02.pdf
SUSPICIOUS — a80520b02.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
36d24c671cbe2eb86890e9ef6d835ee889e9a31ef4cf49facf074a85648f0992 - SHA-1:
0d761da748e98f0d2a17bb5f8bbb3aad26fffe68 - MD5:
0475c626956a0f5b00b85df49796be01 - ssdeep:
3072:qFCeSB9T9O64HjEhp+fizL9Ht7jYp3KpUbUIuAmBqEeIn7k5ziaGrU9ZD:6HSsFQb6izL/HYp3tb5uAmeI7OB - TLSH:
T1674001F3059BEF6D26C7CB13AAEE3449515ECB4890725B6154C82B2CD07C27E1F60A62 - Submitted as: a80520b02.pdf
- File type: pdf · Size: 172847 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/9e5a2a5f-b7e7-46c9-b20c-1832fc19eb2a/35016525158.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=causes%20of%20the%20south%20african%20war%201899%20to%201902%20pdf, https://cdn.shopify.com/s/files/1/0483/7946/1785/files/78439102968.pdf, https://cdn.shopify.com/s/files/1/0505/1704/9516/files/16266228358.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=causes%20of%20the%20south%20african%20war%201899%20to%201902%20pdf
- https://cdn.shopify.com/s/files/1/0483/7946/1785/files/78439102968.pdf
- https://cdn.shopify.com/s/files/1/0505/1704/9516/files/16266228358.pdf
- https://cdn.shopify.com/s/files/1/0484/1701/3912/files/manual_ducati_mini_marcelino.pdf
- https://cdn.shopify.com/s/files/1/0465/9413/0085/files/43514863022.pdf
- https://cdn.shopify.com/s/files/1/0434/4584/6168/files/san_diego_courts_jobs.pdf
- https://s3.amazonaws.com/jedobufudajewu/87396226696.pdf
- https://xanodupujariris.weebly.com/uploads/1/3/0/9/130969381/sadokuxarezug.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/xenemavurinap_jokepirewiteda_fijalezej_gemewije.pdf
- https://finazodaxuvoj.weebly.com/uploads/1/3/2/6/132682535/2156718.pdf
- https://towetebofipu.weebly.com/uploads/1/3/1/4/131437669/5d6626fc71d.pdf
- https://ziripovopibew.weebly.com/uploads/1/3/0/8/130874468/66dd73fc42d.pdf
- https://cdn.shopify.com/s/files/1/0439/8877/9166/files/jeep_roadside_assistance_telephone_number.pdf
- https://cdn.shopify.com/s/files/1/0498/6080/4770/files/the_language_of_medicine_11th_edition_by_davi-ellen_chabner.pdf
- https://cdn.shopify.com/s/files/1/0483/4800/4515/files/lejewemiresujefux.pdf
- https://s3.amazonaws.com/tetazino/xojosanelonupolisobugeri.pdf
- https://s3.amazonaws.com/sugaguxagu/kinaz.pdf
- https://s3.amazonaws.com/fasanag/1974735384.pdf
- https://s3.amazonaws.com/felasorarabipis/subanajederowumupu.pdf
- https://uploads.strikinglycdn.com/files/9e5a2a5f-b7e7-46c9-b20c-1832fc19eb2a/35016525158.pdf
- https://uploads.strikinglycdn.com/files/f45bbb5e-4988-4ea9-b3b2-467bacc43f5f/wavixerajifanuse.pdf
- https://uploads.strikinglycdn.com/files/b4621f55-0030-4b32-9929-e6516d9ca6f0/pepukupakajovawuweza.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- k.cf
- cdn.shopify.com
- s3.amazonaws.com
- xanodupujariris.weebly.com
- vuxozajuje.weebly.com
- finazodaxuvoj.weebly.com
- towetebofipu.weebly.com
- ziripovopibew.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report