SUSPICIOUS — nowagadivon.pdf
SUSPICIOUS — nowagadivon.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (51/100). 1 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
55b5344db72346114f9b3c369e7a7fee00658919486dfc0e91ceb471e95a5d96 - SHA-1:
7f10a39a1f7807ba807d57e1f880c16b53141ee7 - MD5:
14470fa948381a1d5af5a2a447d992db - ssdeep:
768:VgGzpDve3AU/GNP2mSVK4QIZEkwpt1IudNHR2oZZRBDm:GGFDebQIZw/IcNHYoZnBDm - TLSH:
T1803149F711A7DD8C368BEB03AEEB255D558ADB496122D7A04888672CC4BC37C7F44910 - Submitted as: nowagadivon.pdf
- File type: pdf · Size: 39318 bytes
- Verdict: suspicious (51/100)
Detections (1 of 53 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 51/100 is the fusion of 3 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/91adaa41-6911-4ec2-a984-0d10ff4d51e3/87078351247.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=bowflex%20max%20trainer%20m7%20service%20manual, https://uploads.strikinglycdn.com/files/91adaa41-6911-4ec2-a984-0d10ff4d51e3/87078351247.pdf, https://uploads.strikinglycdn.com/files/4421df71-7e5d-42a6-a123-df0a340cd2aa/potesinufanijodoxi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=bowflex%20max%20trainer%20m7%20service%20manual
- https://s3.amazonaws.com/leguvefu/deconstructivismo_arquitectura.pdf
- https://s3.amazonaws.com/zirojopemup/java_brains_spring_mvc.pdf
- https://s3.amazonaws.com/tadovu/714154726.pdf
- https://s3.amazonaws.com/susopuzupure/74047600061.pdf
- https://uploads.strikinglycdn.com/files/91adaa41-6911-4ec2-a984-0d10ff4d51e3/87078351247.pdf
- https://uploads.strikinglycdn.com/files/4421df71-7e5d-42a6-a123-df0a340cd2aa/potesinufanijodoxi.pdf
- https://uploads.strikinglycdn.com/files/8f02c078-0017-4c68-a09d-57837961c5ae/jegoxubugiludixilexukalu.pdf
- https://uploads.strikinglycdn.com/files/9b2b860a-e45a-4dea-8b91-3b20f91bd22c/keketav.pdf
- https://cdn-cms.f-static.net/uploads/4366008/normal_5f8738515c616.pdf
- https://cdn-cms.f-static.net/uploads/4383314/normal_5f8f1e881b3fc.pdf
- https://cdn-cms.f-static.net/uploads/4366959/normal_5f887d443468f.pdf
- https://cdn-cms.f-static.net/uploads/4366029/normal_5f8d8d9368269.pdf
- https://cdn-cms.f-static.net/uploads/4379491/normal_5f8d8819a5e9b.pdf
- https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/cc4139.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/3250b5961ed1.pdf
- https://panidulupeju.weebly.com/uploads/1/3/0/9/130969186/2730194.pdf
- https://zisokilusativ.weebly.com/uploads/1/3/2/3/132303079/jasamatelez.pdf
- https://s3.amazonaws.com/nimuwet/37736843792.pdf
- https://s3.amazonaws.com/levumoduf/berliner_platz_1_neu_intensivtrainer_download.pdf
- https://s3.amazonaws.com/xanebavifamopez/cetoconazol_pomada_bula.pdf
- https://cdn-cms.f-static.net/uploads/4369520/normal_5f91aa304ce71.pdf
- https://cdn-cms.f-static.net/uploads/4374536/normal_5f8aea1299542.pdf
- https://cdn-cms.f-static.net/uploads/4369519/normal_5f89b87c84e57.pdf
- https://cdn-cms.f-static.net/uploads/4375344/normal_5f90ecf1894eb.pdf
Embedded domains
- gettraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- besiwalufeg.weebly.com
- mojivimimujovo.weebly.com
- panidulupeju.weebly.com
- zisokilusativ.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report