SUSPICIOUS — 752275.pdf
SUSPICIOUS — 752275.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4a682b3e23cb783fe5669abdf0be4cb1f0fcd9cb31a773e5dc94b3c6ed28f864 - SHA-1:
7cb9441f826a9828bb3bc3be3651ad6f59cbd573 - MD5:
34d158040bc0e2d9c7f3c8f091f4011c - ssdeep:
768:uygGzpDPppveloF3eWfylpkSRw/kIo6M9v2Qd7s/Nn2eSjFnFH2C8Y:uvGFNpvdfyTkSukIQzd7s/l2eSBnFH2g - TLSH:
T1F8327CF311B3ED4CBA879B43ADFA15A9948ED70861329B64018C7A2DC4BC2BD7E01951 - Submitted as: 752275.pdf
- File type: pdf · Size: 43703 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/c5abd1b5-1256-41ed-98dc-08bf61bd6f13/fubunupibuduwimavuvelel.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=wayne%20pumps%20parts, https://cdn-cms.f-static.net/uploads/4366041/normal_5f870a845c880.pdf, https://cdn-cms.f-static.net/uploads/4365580/normal_5f872c75b1bfd.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=wayne%20pumps%20parts
- https://cdn-cms.f-static.net/uploads/4366041/normal_5f870a845c880.pdf
- https://cdn-cms.f-static.net/uploads/4365580/normal_5f872c75b1bfd.pdf
- https://cdn-cms.f-static.net/uploads/4366360/normal_5f872fc87fc8e.pdf
- https://cdn-cms.f-static.net/uploads/4365602/normal_5f872a6a6c6f1.pdf
- https://site-1037033.mozfiles.com/files/1037033/83598246954.pdf
- https://site-1038995.mozfiles.com/files/1038995/15483755869.pdf
- https://site-1040612.mozfiles.com/files/1040612/10932248911.pdf
- https://uploads.strikinglycdn.com/files/c5abd1b5-1256-41ed-98dc-08bf61bd6f13/fubunupibuduwimavuvelel.pdf
- https://uploads.strikinglycdn.com/files/032479c5-183b-4a4d-bdef-77c7236f5b8a/91113259474.pdf
- https://uploads.strikinglycdn.com/files/816fdcbb-b88f-4a7f-83a9-3f7082193ba6/10812817907.pdf
- https://uploads.strikinglycdn.com/files/90211cf0-e208-4c94-b7b3-6890b30d224d/legonevajiz.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/xojajuv-mitegejitokuxig.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/jozepap.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/caa64.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/bosilo_ginasesif.pdf
- https://zesopupejilit.weebly.com/uploads/1/3/0/7/130738861/67f7767f9a8dfa.pdf
- https://cdn-cms.f-static.net/uploads/4365639/normal_5f8705c80543d.pdf
- https://cdn-cms.f-static.net/uploads/4365563/normal_5f87133a82d62.pdf
- https://cdn-cms.f-static.net/uploads/4366350/normal_5f8714fec4854.pdf
- https://cdn-cms.f-static.net/uploads/4365619/normal_5f86fd187bd3a.pdf
- https://uploads.strikinglycdn.com/files/cc8158c0-379f-4918-8bda-48a26529dc32/69261130920.pdf
- https://uploads.strikinglycdn.com/files/ef960b2f-2252-47a4-96b7-3bec179263d6/10127641034.pdf
- https://uploads.strikinglycdn.com/files/2d3d0b05-f810-46e9-b86e-6857524a51b5/56254838106.pdf
- https://uploads.strikinglycdn.com/files/949214de-fbec-4a0d-b9a9-76a7ea95d569/841764147.pdf
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- site-1037033.mozfiles.com
- site-1038995.mozfiles.com
- site-1040612.mozfiles.com
- uploads.strikinglycdn.com
- gimejexoxixaza.weebly.com
- jufaxexave.weebly.com
- dimaxafazeza.weebly.com
- mogilifus.weebly.com
- zesopupejilit.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report