SUSPICIOUS — 3343239.pdf
SUSPICIOUS — 3343239.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
757aee45bab736203cb68e3569159e02308d3fb00741f09308d2bcfb0b630591 - SHA-1:
838f781351c98c42a751950ee1a4e7f7f7f15764 - MD5:
03aeef7a1f6ada78413d34caca431a8b - ssdeep:
768:6gGzpD1pHFNXB/OArXP11x6+sp2i6L+ZXHI8QYB5O4InBvxJV+0E8in0nP:nGFBpI6h6+spyin1O4aBvxtEDn0nP - TLSH:
T1E3329EF36097DC4C3A8FAF439EAA2159A58AD38C6132D2A014CC776CC4BC9FD6E11651 - Submitted as: 3343239.pdf
- File type: pdf · Size: 43535 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://lulitetuxopibol.weebly.com/uploads/1/3/1/1/131164377/disabojezobid.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=john%20deere%205075e%20technical%20manual, https://puvugaluruwibok.weebly.com/uploads/1/3/4/4/134445294/zorup.pdf, https://jibotofixox.weebly.com/uploads/1/3/4/5/134502829/01525c5.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=john%20deere%205075e%20technical%20manual
- https://puvugaluruwibok.weebly.com/uploads/1/3/4/4/134445294/zorup.pdf
- https://jibotofixox.weebly.com/uploads/1/3/4/5/134502829/01525c5.pdf
- https://lulitetuxopibol.weebly.com/uploads/1/3/1/1/131164377/disabojezobid.pdf
- https://cdn-cms.f-static.net/uploads/4373016/normal_5f895fcdbd19a.pdf
- https://cdn-cms.f-static.net/uploads/4370302/normal_5f8cb983c4da3.pdf
- https://uploads.strikinglycdn.com/files/68721f37-1d54-43fb-b753-f213d95113a0/vufawasilozimodarisesisu.pdf
- https://uploads.strikinglycdn.com/files/1ce1b4e5-e8b9-4771-84cd-3e604cfb08e0/jamadamedujufezaxazutajal.pdf
- https://uploads.strikinglycdn.com/files/a37db67d-3f2d-4f8f-a899-606b21f206bd/16493341255.pdf
- https://uploads.strikinglycdn.com/files/8be60066-3b1e-4d21-9905-31d9eed40876/watoxusomuzu.pdf
- https://uploads.strikinglycdn.com/files/97b68f5f-1d68-4c7c-bc08-99b620ade021/lying_by_sam_harris.pdf
- https://uploads.strikinglycdn.com/files/70dc1a8e-2e63-4d78-bf9c-71fcb58637f5/rejabapibinokonatusami.pdf
- https://cdn.shopify.com/s/files/1/0492/1986/2694/files/girl_guide_songs_with_actions.pdf
- https://cdn.shopify.com/s/files/1/0428/9737/5388/files/lizuzuxav.pdf
- https://cdn.shopify.com/s/files/1/0483/0439/0307/files/jlpt_n3_book.pdf
- https://cdn.shopify.com/s/files/1/0480/3248/1429/files/burlington_return_policy_without_tag.pdf
- https://cdn.shopify.com/s/files/1/0501/5103/0949/files/kiddie_korral_kh3.pdf
- https://cdn.shopify.com/s/files/1/0484/8467/9842/files/famous_artists_word_whizzle_answers.pdf
- https://cdn.shopify.com/s/files/1/0502/6044/3298/files/marlin_papoose_folding_stock_for_sale.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- puvugaluruwibok.weebly.com
- jibotofixox.weebly.com
- lulitetuxopibol.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- E:\0=
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report