SUSPICIOUS — a6c5a9abf.pdf
SUSPICIOUS — a6c5a9abf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
99087de7206475a010994a13674f670b18876ea80ba99dd142d4ec97aa403981 - SHA-1:
f5b3cb29b169a64add5bd694fe86c7d9f022fddd - MD5:
403ab6f27c927452b67d6827e12ec975 - ssdeep:
1536:GU+finQ42L3eoZY13s9ZJneIT5FLWpHudwazRc8GN76FL2jO0LTE:BUinQ42Kh0ZUpHETC8k7G2w - TLSH:
T17B37D0F3216BFDCC3B89AB47DDF6082C25C9D28C71AB997445C8766C85780AE2F11A11 - Submitted as: a6c5a9abf.pdf
- File type: pdf · Size: 73431 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://static1.squarespace.com/static/5fbfff2111f6a4198480a438/t/5fcf5c07caa95a391e6c201d/1607425032856/14055908379.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://trafffi.ru/wb?keyword=adapter%20design%20pattern%20in%20android, https://uploads.strikinglycdn.com/files/a465f7ca-8000-4119-8b86-4a933338d149/megidakavaxugukiv.pdf, https://mejefarekobuk.weebly.com/uploads/1/3/4/3/134338461/f274f5e07b36268.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffi.ru/wb?keyword=adapter%20design%20pattern%20in%20android
- https://uploads.strikinglycdn.com/files/a465f7ca-8000-4119-8b86-4a933338d149/megidakavaxugukiv.pdf
- https://mejefarekobuk.weebly.com/uploads/1/3/4/3/134338461/f274f5e07b36268.pdf
- https://static1.squarespace.com/static/5fbfff2111f6a4198480a438/t/5fcf5c07caa95a391e6c201d/1607425032856/14055908379.pdf
- https://static1.squarespace.com/static/5fc4e843b8467722f1ed819c/t/5fc874a6d6e0cc37e33dad8d/1606972583909/93771615181.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf5c7b173fb5383b99afe5/1606376574217/25644150116.pdf
- https://static1.squarespace.com/static/5fc18713df132613bbc22f2b/t/5fd008907b0a801071fd0511/1607469200383/52001250025.pdf
- https://riwisasivituw.weebly.com/uploads/1/3/1/0/131070703/1055561.pdf
- https://static1.squarespace.com/static/5fc518baf9866f3fd2ef1438/t/5fd02f521c49363a9b4210e1/1607479123688/gubuviwewotovo.pdf
- https://static1.squarespace.com/static/5fc10dd611f6a419848684c6/t/5fc23a21e18c5c478e456961/1606564385207/ffa_history_timeline.pdf
- https://s3.amazonaws.com/lupuvogotog/rosapukuxafimebokivegozix.pdf
- https://static1.squarespace.com/static/5fc17eeec89e1c4b8fc2a697/t/5fc60d39cb3e0f57711f4086/1606815033564/homeless_to_harvard_worksheet.pdf
- https://uploads.strikinglycdn.com/files/ea401fa0-6e50-4016-b40f-c86613e1e466/47984425144.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffi.ru
- uploads.strikinglycdn.com
- mejefarekobuk.weebly.com
- static1.squarespace.com
- riwisasivituw.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report