SUSPICIOUS — 16afd8a6dfe8.pdf
SUSPICIOUS — 16afd8a6dfe8.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ac1d83a046b463565a06bd0e4942e6587015fdec56a27ffbc3653e45b020e571 - SHA-1:
43dd0091e5a41214d1d8570cfe0faf0638ffd760 - MD5:
a3dc85f01c6d4c5fcf20088847ef021b - ssdeep:
768:3gGzpDv3CwnWntndnnSMnBBk9nVUnKVnPynP0nP2nOnLP2C5DlfAtt/CsG/rU3kl:QGF7y2xfAGTWksVS6Htkcc11x - TLSH:
T193318EF75093ED9C3A4BAB53A9EA106E2186C24D6032D77009D8762CC4BCAFDBE11855 - Submitted as: 16afd8a6dfe8.pdf
- File type: pdf · Size: 42869 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://sozivutapadonen.weebly.com/uploads/1/3/1/1/131164462/geponafomi-nipas.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=personal%20and%20possessive%20pronouns%20worksheets%20pdf, https://xetibipu.weebly.com/uploads/1/3/4/5/134528590/ruzewozidi-gosejijugaf.pdf, https://xekixudag.weebly.com/uploads/1/3/4/3/134336078/wawogopapi_vagunipid_pawomuter.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=personal%20and%20possessive%20pronouns%20worksheets%20pdf
- https://xetibipu.weebly.com/uploads/1/3/4/5/134528590/ruzewozidi-gosejijugaf.pdf
- https://xekixudag.weebly.com/uploads/1/3/4/3/134336078/wawogopapi_vagunipid_pawomuter.pdf
- https://zemuxarasojutin.weebly.com/uploads/1/3/4/3/134374283/010bebaff183888.pdf
- https://cdn.shopify.com/s/files/1/0500/5882/1803/files/steps_of_research_proposal.pdf
- https://cdn.shopify.com/s/files/1/0491/5822/6119/files/bpa_graphic_design_promotion_presentation.pdf
- https://sozivutapadonen.weebly.com/uploads/1/3/1/1/131164462/geponafomi-nipas.pdf
- https://dirigesibujov.weebly.com/uploads/1/3/0/9/130969991/vovuje-fujejew.pdf
- https://sagupegijugix.weebly.com/uploads/1/3/4/4/134443219/8eda624e2b.pdf
- https://cdn.shopify.com/s/files/1/0433/4672/2965/files/dipole_antenna_design_in_hfss.pdf
- https://cdn.shopify.com/s/files/1/0493/1131/8182/files/dinufofujonunotofapemoraz.pdf
- https://cdn.shopify.com/s/files/1/0500/0160/8854/files/guitar_tuner_android_2.3.6.pdf
- https://cdn.shopify.com/s/files/1/0491/6183/0599/files/united_nations_correspondence_manual_french.pdf
- https://vikumeniwexawud.weebly.com/uploads/1/3/0/9/130969440/mafuniboj-xelabamokuvitun-kewufesef.pdf
- https://bulipabuwalo.weebly.com/uploads/1/3/4/1/134131868/fufofiduxowi_fonojujuw.pdf
- https://cdn.shopify.com/s/files/1/0502/3825/9355/files/80985566128.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- xetibipu.weebly.com
- xekixudag.weebly.com
- zemuxarasojutin.weebly.com
- cdn.shopify.com
- sozivutapadonen.weebly.com
- dirigesibujov.weebly.com
- sagupegijugix.weebly.com
- vikumeniwexawud.weebly.com
- bulipabuwalo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report