SUSPICIOUS — 2834478.pdf
SUSPICIOUS — 2834478.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
605d4823e077c39b0218e653b7ff0e1ab44ac3f225edeb568f4ed3b0a36705e9 - SHA-1:
e0d3e216fc2634940677170f6325971ddee8289a - MD5:
6f636521c747ebfd916ea0849a3d43fc - ssdeep:
768:CgGzpD/p6DPc9xk5CaqzA0LFppC4sah7FktH/pFz6dywCHbKs6Bm:fGFrp6/5CaoxRP7wfpp6dywKbKs6Bm - TLSH:
T19B31AEF31497ED4C3D8A9B136CAB1565618AC788A173DB60098CBB7CD47C6BCBE10861 - Submitted as: 2834478.pdf
- File type: pdf · Size: 43009 bytes
- Verdict: suspicious (58/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://vopevejefed.weebly.com/uploads/1/3/1/6/131606133/8af7d8b8d4913.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=gowise%20pressure%20cooker%20manual, https://site-1042779.mozfiles.com/files/1042779/bemijil.pdf, https://site-1041498.mozfiles.com/files/1041498/39033633633.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=gowise%20pressure%20cooker%20manual
- https://site-1042779.mozfiles.com/files/1042779/bemijil.pdf
- https://site-1041498.mozfiles.com/files/1041498/39033633633.pdf
- https://site-1039266.mozfiles.com/files/1039266/dobobewewipomikatemevala.pdf
- https://site-1040341.mozfiles.com/files/1040341/30046766803.pdf
- https://cdn-cms.f-static.net/uploads/4365646/normal_5f8716994302e.pdf
- https://uploads.strikinglycdn.com/files/e66acdcb-7cf9-4424-a2e4-f3f744221072/48863117098.pdf
- https://uploads.strikinglycdn.com/files/85254ae3-9402-45d9-aefa-e5cb6648783b/43862634549.pdf
- https://uploads.strikinglycdn.com/files/ccfc4b30-a0c1-4201-b14e-36d36a3d6e49/wolanev.pdf
- https://vopevejefed.weebly.com/uploads/1/3/1/6/131606133/8af7d8b8d4913.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/zidebesirolabavo.pdf
- https://dapujevubo.weebly.com/uploads/1/3/1/4/131438680/lusitumam-wokamos-zuwixuxelaze-sipijota.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/3257372.pdf
- https://uploads.strikinglycdn.com/files/3f035b45-30c9-4a4e-a8f4-04eeb11f7048/tafupunagebeb.pdf
- https://uploads.strikinglycdn.com/files/64dbc9ed-b053-4fe3-ba5b-cd6b5b4028b6/13362324247.pdf
- https://uploads.strikinglycdn.com/files/cede2969-e7f5-480f-bc1f-517314850593/bufibowogol.pdf
- https://uploads.strikinglycdn.com/files/5dde63d1-050c-4885-8f9d-c1ba5a3f47fd/37481082680.pdf
- https://uploads.strikinglycdn.com/files/998c797f-ab26-41c9-820e-48f64919e938/mujusotas.pdf
- https://cdn.shopify.com/s/files/1/0478/7260/6374/files/domigexivilemifin.pdf
- https://cdn.shopify.com/s/files/1/0432/3357/5075/files/12449439408.pdf
- https://cdn.shopify.com/s/files/1/0480/4372/0868/files/xipeziredinibozuzurona.pdf
- https://cdn.shopify.com/s/files/1/0482/2931/8808/files/golf_clash_tommy_ring_guide.pdf
- https://cdn.shopify.com/s/files/1/0441/4291/9832/files/fill_me_up_jesus_culture_chords.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- site-1042779.mozfiles.com
- site-1041498.mozfiles.com
- site-1039266.mozfiles.com
- site-1040341.mozfiles.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- vopevejefed.weebly.com
- jawasolasazilem.weebly.com
- dapujevubo.weebly.com
- vuxozajuje.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report