SUSPICIOUS — 0a61efbba.pdf
SUSPICIOUS — 0a61efbba.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3bb2276bfea8f869e169f2c4099df3aa8843a6a667491fe5001b895a28c9b15b - SHA-1:
42cebf2d4dfa88d1a0a87c6a7ef5841efa8aa315 - MD5:
4f0e28c32efd96ae340c31b8f562a932 - ssdeep:
768:EgGzpDSpyn6/DOKQ3/3swG5zIgeuqFk48x+LBLxMrB:xGFmpmGzIt1Fkb+1xMrB - TLSH:
T117317CF310A3FC4C7ECB9F136DEA146A654AD7886126E76014887B2CD0BCAED6E10561 - Submitted as: 0a61efbba.pdf
- File type: pdf · Size: 42137 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/2e36d331-0900-462d-a456-5e5c849d1279/le_genre_et_le_nombre.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=types%20of%20thin%20films%20pdf, https://uploads.strikinglycdn.com/files/2e36d331-0900-462d-a456-5e5c849d1279/le_genre_et_le_nombre.pdf, https://uploads.strikinglycdn.com/files/8176373f-63a0-49c1-9f38-0c5658d24088/48626475230.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=types%20of%20thin%20films%20pdf
- https://uploads.strikinglycdn.com/files/2e36d331-0900-462d-a456-5e5c849d1279/le_genre_et_le_nombre.pdf
- https://uploads.strikinglycdn.com/files/8176373f-63a0-49c1-9f38-0c5658d24088/48626475230.pdf
- https://uploads.strikinglycdn.com/files/c53d9abd-a6c7-4af7-83c8-fba51853a3cc/36643636227.pdf
- https://uploads.strikinglycdn.com/files/b43c32f8-e2b9-4be4-aa85-15bebd070ac1/4366986322.pdf
- https://uploads.strikinglycdn.com/files/09e1e7e1-b22e-4457-9394-503abb548b35/jodivujigape.pdf
- https://uploads.strikinglycdn.com/files/18f637da-4aed-447d-b42d-8d97e94b2c21/50422587655.pdf
- https://uploads.strikinglycdn.com/files/a3d09aa6-4a8e-4e33-a2a0-594d9a151c90/43002663201.pdf
- https://cdn.shopify.com/s/files/1/0439/2137/5387/files/dezezilonanopoleri.pdf
- https://cdn.shopify.com/s/files/1/0498/8423/3886/files/preparation_of_soap_from_palm_oil.pdf
- https://cdn.shopify.com/s/files/1/0496/3916/2005/files/446330470.pdf
- https://cdn.shopify.com/s/files/1/0479/6694/5447/files/bidiseberuxajitepapo.pdf
- https://cdn.shopify.com/s/files/1/0493/2046/0447/files/wojanezinisefig.pdf
- https://cdn.shopify.com/s/files/1/0266/7967/3011/files/adultfanfiction_net_naruto.pdf
- https://terarawuterojuz.weebly.com/uploads/1/3/0/7/130739827/f718c26b91.pdf
- https://pinonomobeberex.weebly.com/uploads/1/3/4/3/134318871/d142f4d940.pdf
- https://buluzuzumaz.weebly.com/uploads/1/3/1/6/131636727/vusidosotuzoxe_xudoxav.pdf
- https://fufivivol.weebly.com/uploads/1/3/0/8/130873849/8a56f49.pdf
- https://cdn.shopify.com/s/files/1/0431/6443/4589/files/90999261934.pdf
- https://cdn.shopify.com/s/files/1/0432/7686/1606/files/choki_choki_mobile_legends_ar_apk.pdf
- https://cdn.shopify.com/s/files/1/0428/9085/4566/files/zuwukoriwo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- terarawuterojuz.weebly.com
- pinonomobeberex.weebly.com
- buluzuzumaz.weebly.com
- fufivivol.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report