SUSPICIOUS — piwoveruta.pdf
SUSPICIOUS — piwoveruta.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7e84739a4757a78cb4f8129ad2ab952d0ef0c9a706f37791277ba901acc92b13 - SHA-1:
73c59aa633bf311604fc3f28b6b19bf874f019e0 - MD5:
68c3906ada94d0ad6135c7dc8f62d2eb - ssdeep:
1536:sGFQwJDO4I7PUXBOWUapvDPIouXFUGInJv/fKN2eR6cT:JFQG0UX4WNpvDIF1UGInJPKMeRZ - TLSH:
T10F38D0F34497DE8CA68AAB43EDD9009A405AC6CD6167E7A418CC6A7CC47C7FF6D00891 - Submitted as: piwoveruta.pdf
- File type: pdf · Size: 77111 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/5646d024-f1b4-4ed0-b07e-28cdbee4c377/51932665960.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=ecological+succession+activity, https://uploads.strikinglycdn.com/files/5646d024-f1b4-4ed0-b07e-28cdbee4c377/51932665960.pdf, https://uploads.strikinglycdn.com/files/43d52c65-2238-48fb-b9d7-c261b4ef76e6/86162517721.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=ecological+succession+activity
- https://uploads.strikinglycdn.com/files/5646d024-f1b4-4ed0-b07e-28cdbee4c377/51932665960.pdf
- https://uploads.strikinglycdn.com/files/43d52c65-2238-48fb-b9d7-c261b4ef76e6/86162517721.pdf
- https://uploads.strikinglycdn.com/files/28d54397-49d5-406b-b33b-a0943a3a5243/38212069215.pdf
- https://uploads.strikinglycdn.com/files/f10be40e-9d7f-4f79-a17a-5e9038005398/41627089066.pdf
- https://uploads.strikinglycdn.com/files/110b499f-5b5b-4109-89da-9bef299f5712/32206541519.pdf
- https://uploads.strikinglycdn.com/files/6b265deb-e643-47dc-96ad-d1e6995b4c72/78174208622.pdf
- https://uploads.strikinglycdn.com/files/15abf4b0-edcc-4bfb-934c-2c3624aaca0c/jekipojapezufajazogida.pdf
- https://uploads.strikinglycdn.com/files/0b6b51d5-b427-4444-9105-34529320db7d/81028867054.pdf
- https://uploads.strikinglycdn.com/files/2db5f8e6-7e0e-44f9-a01e-595c35f075c5/wetozegik.pdf
- http://risumiva.portellowinecafe.com/uploads/1/3/2/8/132816066/b54c466c.pdf
- http://files.lifewithtoribrand.com/uploads/1/3/1/3/131379980/nasomavoj_tobok.pdf
- http://files.roboticfirefighters.com/uploads/1/3/1/1/131164168/6048d.pdf
- http://files.margolisphilosophy.com/uploads/1/3/0/7/130738921/lelezitubuzejug-gipikutanon.pdf
- http://files.osvaldobudon.org/uploads/1/3/1/3/131383928/5436014.pdf
- https://cdn.shopify.com/s/files/1/0438/1235/6253/files/monopoly_jackpot_second_chance_ma.pdf
- https://cdn.shopify.com/s/files/1/0462/2352/3994/files/vesedagegukitotenoganolej.pdf
- https://cdn.shopify.com/s/files/1/0435/4218/4095/files/last_dance_with_mary_jane_harmonica_notes.pdf
- https://cdn.shopify.com/s/files/1/0492/6786/7804/files/how_to_use_ninja_blender_professional.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- risumiva.portellowinecafe.com
- files.lifewithtoribrand.com
- files.roboticfirefighters.com
- files.margolisphilosophy.com
- files.osvaldobudon.org
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report