SUSPICIOUS — 1395216.pdf
SUSPICIOUS — 1395216.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
37b6c8d2b4a96fd4f18d5cf0b6d31da70e3d48d581a151b1f81284ff6cda1477 - SHA-1:
75bd704d1238773ee77acc03b96d6ae472df7a18 - MD5:
ba70a1f1e74e01931677096d78f57d36 - ssdeep:
768:CgGzpDCpM99PFwRg7ltoO3vS0p0MSs1m10dR276LIeBsSl1fY/39nJlrl4:fGFupY/ZNEq06LI7SA/39Jlrl4 - TLSH:
T1D1329EF71067ED8C7B8EAB079EAE015A648AC78D703693500598772DC0BCBFD6E10661 - Submitted as: 1395216.pdf
- File type: pdf · Size: 43772 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://nobinetezo.weebly.com/uploads/1/3/0/9/130969761/xoteramerosikaja.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=hp%20pavilion%20gaming%20laptop%20review, https://nobinetezo.weebly.com/uploads/1/3/0/9/130969761/xoteramerosikaja.pdf, https://papunagaku.weebly.com/uploads/1/3/1/3/131384156/2842d.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=hp%20pavilion%20gaming%20laptop%20review
- https://nobinetezo.weebly.com/uploads/1/3/0/9/130969761/xoteramerosikaja.pdf
- https://papunagaku.weebly.com/uploads/1/3/1/3/131384156/2842d.pdf
- https://sujajikozodes.weebly.com/uploads/1/3/1/3/131384638/volefesa.pdf
- https://cdn.shopify.com/s/files/1/0480/4975/0175/files/learning_teaching_jim_scrivener_download.pdf
- https://cdn.shopify.com/s/files/1/0432/0890/0768/files/descargar_chromecast_para_android_apk.pdf
- https://cdn.shopify.com/s/files/1/0501/9031/9804/files/kiwof.pdf
- https://cdn.shopify.com/s/files/1/0481/8432/8344/files/47300537667.pdf
- https://uploads.strikinglycdn.com/files/ea2abfb2-bbc6-4216-b3e1-133f495f69ee/14414882826.pdf
- https://uploads.strikinglycdn.com/files/a9c93d8a-225f-44cd-84f5-a72ec5f38445/rojesesajitopo.pdf
- https://uploads.strikinglycdn.com/files/e7c4d21f-37f3-4ef1-8438-7e65421bb214/timelimakix.pdf
- https://uploads.strikinglycdn.com/files/f731639e-afc4-41f3-ad2e-df341e460089/ponumiwaroxo.pdf
- https://uploads.strikinglycdn.com/files/0c483bc7-df16-4664-9a3e-ad33fdf146ed/42211599969.pdf
- https://s3.amazonaws.com/donake/burisasewa.pdf
- https://s3.amazonaws.com/susopuzupure/23100762748.pdf
- https://cdn.shopify.com/s/files/1/0466/5281/7573/files/97202681148.pdf
- https://cdn.shopify.com/s/files/1/0435/5417/7185/files/scratch_pad_for_android.pdf
- https://cdn.shopify.com/s/files/1/0497/2252/3805/files/wiwulovutuzar.pdf
- https://s3.amazonaws.com/wonoti/29046290687.pdf
- https://s3.amazonaws.com/wonoti/blank_risk_assessment_template.pdf
- https://s3.amazonaws.com/fasanag/o_reilly_python_cookbook_3rd_edition.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- nobinetezo.weebly.com
- papunagaku.weebly.com
- sujajikozodes.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- s3.amazonaws.com
- m.cc
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report