SUSPICIOUS — 5e36710.pdf
SUSPICIOUS — 5e36710.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7ea9510922dba78a471932a642ea33b64315ee60fb1b3042ca160aeca12b95fb - SHA-1:
9d2fafbf979a72c5c5550594b1734ac802a9fe50 - MD5:
ac868b55ed8269b2fd4033263bdcf644 - ssdeep:
768:AgGzpDqeC0+b27R4a9PRP1zJIun1SKNBihOeX1cC5unFxBHEEkWDyIRufv8MRZrI:NGFOelYmBi8iP5uFzEEk64k8pN4fD - TLSH:
T11A34AEF32097DC4C7B8BAB4399FB10AE50D9E78D6136D66059883B6CC1BC6AC7E50460 - Submitted as: 5e36710.pdf
- File type: pdf · Size: 54925 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/taladine-wirule-zufosedali.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=job%20application%20letter%20exercise%20pdf, https://cdn.shopify.com/s/files/1/0437/3915/2535/files/sample_cover_letter_for_warehouse_job_with_no_experience.pdf, https://cdn.shopify.com/s/files/1/0268/8863/4547/files/22780104844.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=job%20application%20letter%20exercise%20pdf
- https://s3.amazonaws.com/sugaguxagu/barixunesawaturiwafumeka.pdf
- https://s3.amazonaws.com/zirojopemup/lijagaxovinepezaz.pdf
- https://s3.amazonaws.com/jezaxojipevu/pantera_cemetery_gates_tab.pdf
- https://s3.amazonaws.com/kavitokolezub/lozizu.pdf
- https://s3.amazonaws.com/bokofapig/99979197073.pdf
- https://cdn.shopify.com/s/files/1/0437/3915/2535/files/sample_cover_letter_for_warehouse_job_with_no_experience.pdf
- https://cdn.shopify.com/s/files/1/0268/8863/4547/files/22780104844.pdf
- https://cdn.shopify.com/s/files/1/0486/2260/0350/files/47886259297.pdf
- https://cdn.shopify.com/s/files/1/0482/8007/6449/files/sas_zombie_assault_2_unblocked_games_77.pdf
- https://cdn.shopify.com/s/files/1/0485/8154/2048/files/illuminate_publishing_food_preparation_and_nutrition.pdf
- https://s3.amazonaws.com/henghuili-files2/33537607767.pdf
- https://s3.amazonaws.com/pazifetanegapu/22869104679.pdf
- https://s3.amazonaws.com/fasanag/nafalu.pdf
- https://s3.amazonaws.com/wonoti/movevevodudijamavubifijiv.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/taladine-wirule-zufosedali.pdf
- https://jalewigevat.weebly.com/uploads/1/3/2/6/132681207/ee27b50c64faae.pdf
- https://nipufijupetobug.weebly.com/uploads/1/3/1/4/131482996/bezawubusedufone.pdf
- https://cdn.shopify.com/s/files/1/0497/8311/1831/files/shakira_el_dorado_movie_theater.pdf
- https://cdn.shopify.com/s/files/1/0497/9746/4226/files/11333812931.pdf
- https://cdn.shopify.com/s/files/1/0481/5103/6055/files/15052340929.pdf
- https://cdn-cms.f-static.net/uploads/4370985/normal_5f90345c4078f.pdf
- https://cdn-cms.f-static.net/uploads/4366040/normal_5f879d5228a4b.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f86f96a9ba48.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- s3.amazonaws.com
- cdn.shopify.com
- wepugimi.weebly.com
- jalewigevat.weebly.com
- nipufijupetobug.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report