SUSPICIOUS — 944560.pdf
SUSPICIOUS — 944560.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5b4a326e38e718f04ed27854ef49a039c577407c58839e92b9836d58248d9d25 - SHA-1:
f6ba6c5bc728f82582dc61b9e3e8a1f4b9d28bb5 - MD5:
4bc0112c0675df4e4902a9e964060feb - ssdeep:
768:PgGzpDbpT0EEruKka1a+IsHojbw4JKYQxY4dSojAcdcLjodNkF:4GFPpjc4JK3/dSojFdgMdNkF - TLSH:
T15C317DF350A7ED4CBA8BAB43BDA7106A658AC7886037D760558C273CD17C2BD7E10861 - Submitted as: 944560.pdf
- File type: pdf · Size: 41482 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://natizupasa.weebly.com/uploads/1/3/1/4/131437725/2807748.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=tauba%20tumhare%20yeh%20ishare%20mp3%20downloa, https://cdn.shopify.com/s/files/1/0439/3703/8491/files/bus_driving_game_apk_pure.pdf, https://cdn.shopify.com/s/files/1/0496/1746/9604/files/16991163125.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=tauba%20tumhare%20yeh%20ishare%20mp3%20downloa
- https://cdn.shopify.com/s/files/1/0439/3703/8491/files/bus_driving_game_apk_pure.pdf
- https://cdn.shopify.com/s/files/1/0496/1746/9604/files/16991163125.pdf
- https://cdn.shopify.com/s/files/1/0496/6334/4797/files/nashua_mall_hours.pdf
- https://cdn.shopify.com/s/files/1/0484/0256/3232/files/minecraft_lava_block_id.pdf
- https://cdn.shopify.com/s/files/1/0436/6509/6857/files/dosalozavefujezuf.pdf
- https://natizupasa.weebly.com/uploads/1/3/1/4/131437725/2807748.pdf
- https://uploads.strikinglycdn.com/files/b72fa349-c254-4260-b614-bef4d8c42266/85748645183.pdf
- https://uploads.strikinglycdn.com/files/d1d8e0a9-bf46-4ac0-94db-0ea7c989e16d/59784818036.pdf
- https://uploads.strikinglycdn.com/files/9f89c35b-ceba-49da-8ca7-eaca6b1b0f7a/tulenijukofadokugizip.pdf
- https://uploads.strikinglycdn.com/files/c4d673f7-10ce-4522-8b81-b6487073b367/29114142545.pdf
- https://uploads.strikinglycdn.com/files/9aff9376-4319-4060-b6d4-25d7b2977c44/42730258735.pdf
- https://uploads.strikinglycdn.com/files/0c7fd5c4-8795-4534-8bff-b70516739932/55792329836.pdf
- https://uploads.strikinglycdn.com/files/2e61fadc-a98f-47ea-a9c6-9cc2743a4b10/32025882866.pdf
- https://uploads.strikinglycdn.com/files/bb19bd96-58b7-40f1-8681-c0db8fa1f645/55106895355.pdf
- https://uploads.strikinglycdn.com/files/e9d66a3b-803b-4a4f-9793-cd6acf9349c0/27029119570.pdf
- https://rozolabo.weebly.com/uploads/1/3/0/8/130814594/7777132.pdf
- https://panidulupeju.weebly.com/uploads/1/3/0/9/130969186/riwamiseki.pdf
- https://dotofinadi.weebly.com/uploads/1/3/0/7/130740455/57574ebd8.pdf
- https://pejopazuzaguwoz.weebly.com/uploads/1/3/2/8/132815183/692133.pdf
- https://cdn.shopify.com/s/files/1/0438/4253/5581/files/recorder_belt_songs_with_letters.pdf
- https://cdn.shopify.com/s/files/1/0501/5289/8739/files/90037496853.pdf
- https://cdn.shopify.com/s/files/1/0498/4723/8811/files/42565685349.pdf
- https://cdn.shopify.com/s/files/1/0497/3497/5639/files/linear_relations_worksheets.pdf
- https://cdn.shopify.com/s/files/1/0437/5950/1464/files/gemufibed.pdf
Embedded domains
- cctraff.ru
- cdn.shopify.com
- natizupasa.weebly.com
- uploads.strikinglycdn.com
- rozolabo.weebly.com
- panidulupeju.weebly.com
- dotofinadi.weebly.com
- pejopazuzaguwoz.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report