SUSPICIOUS — 3d769d6b12.pdf
SUSPICIOUS — 3d769d6b12.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
646e7e29caf31edfc02ea0344061a68a453cb54a9d8a789627314c02f8d6a621 - SHA-1:
1b571ec328620acfef20df11d8f7700f2d1bc86d - MD5:
78d6c3e1b0435a227ab5734dcc3d0b3e - ssdeep:
768:M0gGzpDoe9y5ITWk19nCURtETMOerHwDyQIb9/iaFtq3qejnHSSWE5MLKADrlPoO:0GFcekkPrzEYGa9MbnySWRFAmG1M - TLSH:
T11D359EF3019BDE8DB68AAB03AAF61056314AD78C71269770198C7B7CC57C2BC7E11850 - Submitted as: 3d769d6b12.pdf
- File type: pdf · Size: 57728 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/xenemavurinap_jokepirewiteda_fijalezej_gemewije.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=cissp%20official%20study%20guide%208th%20edition%20pdf%20download, https://uploads.strikinglycdn.com/files/684ed1cd-2b13-46a2-9dc4-3a4a30039e01/32242818041.pdf, https://uploads.strikinglycdn.com/files/893620c0-450a-4760-9b41-c16a1f2feed4/21042918487.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=cissp%20official%20study%20guide%208th%20edition%20pdf%20download
- https://uploads.strikinglycdn.com/files/684ed1cd-2b13-46a2-9dc4-3a4a30039e01/32242818041.pdf
- https://uploads.strikinglycdn.com/files/893620c0-450a-4760-9b41-c16a1f2feed4/21042918487.pdf
- https://uploads.strikinglycdn.com/files/2d76fb6a-3267-4899-b756-bf306e33461b/quien_cuenta_las_estrellas_lois_lowry.pdf
- https://s3.amazonaws.com/henghuili-files2/ascii_hex_table.pdf
- https://s3.amazonaws.com/kavitokolezub/waviwog.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/xenemavurinap_jokepirewiteda_fijalezej_gemewije.pdf
- https://buveziketi.weebly.com/uploads/1/3/1/3/131398526/jotepibumobudino.pdf
- https://mofivekirupu.weebly.com/uploads/1/3/2/7/132740685/lufogu-danik.pdf
- https://uploads.strikinglycdn.com/files/7deb756d-209e-4363-ab68-d1ac88d0d06e/resuzewolazimoxun.pdf
- https://uploads.strikinglycdn.com/files/a2c3cf23-70c3-4e3c-81c1-63c865f0a1e2/dodge_hellcat_red_eye.pdf
- https://uploads.strikinglycdn.com/files/b7147697-001e-4efb-868b-b8ca3c2c8ac1/bovufirisagix.pdf
- https://uploads.strikinglycdn.com/files/ae311b76-0e9d-47a5-98b7-67eb2028c3b6/48026430766.pdf
- https://cdn.shopify.com/s/files/1/0497/8661/8017/files/wedufekave.pdf
- https://cdn.shopify.com/s/files/1/0435/8258/7039/files/fevekebeve.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- vuxozajuje.weebly.com
- buveziketi.weebly.com
- mofivekirupu.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report