SUSPICIOUS — 517984138e1fcbe.pdf
SUSPICIOUS — 517984138e1fcbe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4149c82317eae9468d2998bad7dcd4973b3f8e61aaa9da18ff8ee7e2ca2a98ea - SHA-1:
a1a98ba852522d033f9f7a800363858719f17a40 - MD5:
9f60f0a22d098ffe873f382a54d32874 - ssdeep:
1536:cGFKpyq7ft/Bfm4lqOlEAl/0Vn8OaCxp3Le5uD8W2:5FKpfTt/BuuqcEq7OaMteI0 - TLSH:
T1CC339EF351A3ED8C7DC68F03BDF61595604AC78D6232A3A054893B6CC47C9BE6E10A61 - Submitted as: 517984138e1fcbe.pdf
- File type: pdf · Size: 52306 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://lipowuripipu.weebly.com/uploads/1/3/1/3/131378852/1c221f2837cd6f0.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=canterbury%20tales%20general%20prologue%20st, https://site-1039494.mozfiles.com/files/1039494/wevox.pdf, https://site-1042889.mozfiles.com/files/1042889/wepivadane.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=canterbury%20tales%20general%20prologue%20st
- https://site-1039494.mozfiles.com/files/1039494/wevox.pdf
- https://site-1042889.mozfiles.com/files/1042889/wepivadane.pdf
- https://site-1038351.mozfiles.com/files/1038351/63597019142.pdf
- https://site-1039547.mozfiles.com/files/1039547/63585937768.pdf
- https://site-1038908.mozfiles.com/files/1038908/gumulamaliwekodepuwelipup.pdf
- https://site-1038749.mozfiles.com/files/1038749/xudaxunonatigudezupi.pdf
- https://site-1036652.mozfiles.com/files/1036652/xofotevagexobajowovupuw.pdf
- https://lipowuripipu.weebly.com/uploads/1/3/1/3/131378852/1c221f2837cd6f0.pdf
- https://lifagixuwemup.weebly.com/uploads/1/3/0/9/130969738/kosoviwubifano.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/9232432.pdf
- https://zuxuzesis.weebly.com/uploads/1/3/1/4/131438019/6648025.pdf
- https://uploads.strikinglycdn.com/files/62a1a9a7-f1e3-4698-a3eb-1d9fe2d5fa0b/38018766354.pdf
- https://uploads.strikinglycdn.com/files/59aae0dc-d4de-4040-a14a-9c01b1eadc6c/35850926857.pdf
- https://uploads.strikinglycdn.com/files/260e5d0f-b083-49dc-bc4a-2bc1904f21d3/tizudixerevutej.pdf
- https://uploads.strikinglycdn.com/files/597e0694-3c54-49f1-9e38-0a9460c45196/13729787436.pdf
- https://uploads.strikinglycdn.com/files/a6b4b4fa-0fb8-468d-9790-6516a5c65258/6221672141.pdf
- https://uploads.strikinglycdn.com/files/1a5699d3-9092-4021-b87f-7bf5fee1ee4b/27873577204.pdf
- https://uploads.strikinglycdn.com/files/b9b05a98-3edf-4c2e-9b08-1408e9df79cf/20634055718.pdf
- https://uploads.strikinglycdn.com/files/2545d842-027b-472e-b852-db313eb50901/dagekatata.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- site-1039494.mozfiles.com
- site-1042889.mozfiles.com
- site-1038351.mozfiles.com
- site-1039547.mozfiles.com
- site-1038908.mozfiles.com
- site-1038749.mozfiles.com
- site-1036652.mozfiles.com
- lipowuripipu.weebly.com
- lifagixuwemup.weebly.com
- jawasolasazilem.weebly.com
- zuxuzesis.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report