SUSPICIOUS — af5fb769e04.pdf
SUSPICIOUS — af5fb769e04.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4daa1d6f6b45ebf079e0b7a573405d2d32bbcde86ad2adce1b969aa6883a30d2 - SHA-1:
1f5a9021e533a6c72e3b2b8e8f63148fc2c5c508 - MD5:
26333c763b94838243f79ef0de26f8d6 - ssdeep:
768:hgGzpDnQyX/noJUqQKaM3zdL/GLBjTePzjWPxSeShQywLM0qMC:SGFzjWBaMDtCBjaP3XeShQysM0qf - TLSH:
T13E329EF300A3EDCC7A87DB136DB72566648AC74C62329764148D776DC8BC2BCAE11921 - Submitted as: af5fb769e04.pdf
- File type: pdf · Size: 46662 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://wesujugureju.weebly.com/uploads/1/3/0/8/130874517/f812834d1.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=area%20do%20losango%20exercicios%20pdf, https://uploads.strikinglycdn.com/files/572c1736-4ad4-4f3a-97b2-9861237e1e16/gimabolaxini.pdf, https://uploads.strikinglycdn.com/files/149794a9-58cc-48cf-84ab-c67a279481a8/10589294124.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=area%20do%20losango%20exercicios%20pdf
- https://uploads.strikinglycdn.com/files/572c1736-4ad4-4f3a-97b2-9861237e1e16/gimabolaxini.pdf
- https://uploads.strikinglycdn.com/files/149794a9-58cc-48cf-84ab-c67a279481a8/10589294124.pdf
- https://uploads.strikinglycdn.com/files/b2008d94-5fc9-4481-b950-97e525999251/ukulele_tabs_download.pdf
- https://wesujugureju.weebly.com/uploads/1/3/0/8/130874517/f812834d1.pdf
- https://wonigebegi.weebly.com/uploads/1/3/1/6/131606731/mogilu_zalavibadiba_poniwarapodax.pdf
- https://viziwebaf.weebly.com/uploads/1/3/3/9/133999863/xilusowaxezat-mutikopos.pdf
- https://cdn-cms.f-static.net/uploads/4369920/normal_5f8874fdb9d7d.pdf
- https://cdn-cms.f-static.net/uploads/4367648/normal_5f8b478a8c8b9.pdf
- https://cdn-cms.f-static.net/uploads/4366324/normal_5f8716b1d374f.pdf
- https://cdn-cms.f-static.net/uploads/4370092/normal_5f8c83d3242dc.pdf
- https://risimukino.weebly.com/uploads/1/3/1/3/131383953/6143331.pdf
- https://norumevi.weebly.com/uploads/1/3/0/9/130969469/dde7339725.pdf
- https://jesasifewom.weebly.com/uploads/1/3/1/4/131453969/nomur_womewulivusev.pdf
- https://desaviguwogo.weebly.com/uploads/1/3/1/8/131871994/33f825c3ca9.pdf
- https://leruzifu.weebly.com/uploads/1/3/2/3/132302941/34642.pdf
- https://vewutaniwem.weebly.com/uploads/1/3/0/8/130873717/6a9a9daeda.pdf
- https://xusawoji.weebly.com/uploads/1/3/0/7/130739635/2dc2a905509c51.pdf
- https://mefemanodi.weebly.com/uploads/1/3/1/4/131454269/6305813.pdf
- https://vodipewelo.weebly.com/uploads/1/3/1/6/131637384/8009e.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- wesujugureju.weebly.com
- wonigebegi.weebly.com
- viziwebaf.weebly.com
- cdn-cms.f-static.net
- risimukino.weebly.com
- norumevi.weebly.com
- jesasifewom.weebly.com
- desaviguwogo.weebly.com
- leruzifu.weebly.com
- vewutaniwem.weebly.com
- xusawoji.weebly.com
- mefemanodi.weebly.com
- vodipewelo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report