SUSPICIOUS — 5021560.pdf
SUSPICIOUS — 5021560.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7ab5405036e8a22f8ed7aa18fca35515487d535dce0a378b50cb19de7f937dbf - SHA-1:
f90ec19e152026021c32214a53d11dc21ae5789a - MD5:
87c2d27fc9611dfe5f376cb112a6c1bd - ssdeep:
768:PgGzpDvpuGbBFdt7yNgRofUh9KQ6hntr4+tv/8r849pNJDBJyMQE4yla/w2:4GFbpCSIVvdkr849bJSMZla/w2 - TLSH:
T1C6328DF34083ED8D7AC99B43ADAB015A518ED38D6136A754108C776CD9BC6FEBE10860 - Submitted as: 5021560.pdf
- File type: pdf · Size: 45966 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://sijevunima.weebly.com/uploads/1/3/1/8/131859613/kemodufedafuxedif.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=sql%20for%20dummies%202019%20pdf, https://vekejuritikoj.weebly.com/uploads/1/3/1/8/131857631/lumurefimuwav-nalexo-fewajugakeka-ributesila.pdf, https://sijevunima.weebly.com/uploads/1/3/1/8/131859613/kemodufedafuxedif.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=sql%20for%20dummies%202019%20pdf
- https://vekejuritikoj.weebly.com/uploads/1/3/1/8/131857631/lumurefimuwav-nalexo-fewajugakeka-ributesila.pdf
- https://sijevunima.weebly.com/uploads/1/3/1/8/131859613/kemodufedafuxedif.pdf
- https://zoveponezewuda.weebly.com/uploads/1/3/0/7/130738822/sefimas.pdf
- https://uploads.strikinglycdn.com/files/d5dbacbf-6aeb-42bd-be32-3139f3e35b62/32324111318.pdf
- https://uploads.strikinglycdn.com/files/ec2477de-6968-45c5-b70d-222706948de9/55792521647.pdf
- https://uploads.strikinglycdn.com/files/c3ec5f69-6086-477e-8207-ce1b980f24ee/gufijakinamuwuk.pdf
- https://uploads.strikinglycdn.com/files/63647501-3153-4411-8190-d34fbc003df4/24200060712.pdf
- https://uploads.strikinglycdn.com/files/f5b848a1-09f9-4d92-a4cd-44122d7a010c/rigawenebajipubelox.pdf
- https://cdn.shopify.com/s/files/1/0437/7001/9994/files/inesss_infection_urinaire_guide.pdf
- https://cdn.shopify.com/s/files/1/0487/9296/1189/files/duvajavuloma.pdf
- https://cdn.shopify.com/s/files/1/0491/9135/4534/files/origami_dinosaurs_easy_instructions.pdf
- https://cdn.shopify.com/s/files/1/0437/6199/1841/files/logemifufabelavax.pdf
- https://cdn.shopify.com/s/files/1/0462/3876/1109/files/89833075939.pdf
- https://cdn.shopify.com/s/files/1/0427/8360/4903/files/81220345247.pdf
- https://uploads.strikinglycdn.com/files/ffaee8f8-2628-4e07-916b-e977fb2a02e0/44843507231.pdf
- https://uploads.strikinglycdn.com/files/285e16a1-aa69-43f7-b9a4-c9d2830cda9e/fajivef.pdf
- https://uploads.strikinglycdn.com/files/6267a4b4-65b6-4661-9a01-5d04d01e52f5/wosugadetunelonedewed.pdf
- https://uploads.strikinglycdn.com/files/ab046884-89a3-4673-916c-b8fc01fcb90c/3941771327.pdf
- https://uploads.strikinglycdn.com/files/df0ccc72-b605-4db6-9bfe-f2a8e4309c93/funny_alexa_voice_commands.pdf
- https://cdn.shopify.com/s/files/1/0484/8916/9046/files/wolf_bow_steps_reddit.pdf
- https://cdn.shopify.com/s/files/1/0484/3841/1422/files/10380042941.pdf
- https://cdn.shopify.com/s/files/1/0485/0250/5627/files/five_nights_at_anime_game_play.pdf
- https://cdn.shopify.com/s/files/1/0484/6996/7013/files/outer_worlds_achievement_guide.pdf
- https://cdn.shopify.com/s/files/1/0483/5072/4249/files/lujenejaranixud.pdf
Embedded domains
- ggtraff.ru
- vekejuritikoj.weebly.com
- sijevunima.weebly.com
- zoveponezewuda.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report