SUSPICIOUS — ledevogotud-meduto.pdf
SUSPICIOUS — ledevogotud-meduto.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ad7bfbc732f95e5dd0ae51332743b999fa5106b16a6e101f0a64f791f6ba709f - SHA-1:
43d4ee5515f74b06f1e6852bc8dcdeb89dab1d95 - MD5:
ca1cd4d0e3bade267ab677e893c4b9f8 - ssdeep:
768:ygGzpDapMgh8cTT99pOIiZIoCC0npJ+sHPpwe8XtGc0ChhIwR8kOZZYdU:vGFupMER9Sz0ChhIDkOZqdU - TLSH:
T1C4338DF301A3ED4C7A87DB83AEBA2659A189DA455032D7605588773CC0BC7BD7F10A11 - Submitted as: ledevogotud-meduto.pdf
- File type: pdf · Size: 48632 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/844fdd87-b37c-4194-8670-3fa0eead9a33/gewaxagafefas.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=breakin%202%20electric%20boogaloo%20t%C3%A9l%C3%A9char, https://cdn.shopify.com/s/files/1/0481/3884/6371/files/p_assessment_in_perianesthesia_nursing.pdf, https://cdn.shopify.com/s/files/1/0440/1682/8581/files/canon_ae_1_instruction_manual.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=breakin%202%20electric%20boogaloo%20t%C3%A9l%C3%A9char
- https://cdn.shopify.com/s/files/1/0481/3884/6371/files/p_assessment_in_perianesthesia_nursing.pdf
- https://cdn.shopify.com/s/files/1/0440/1682/8581/files/canon_ae_1_instruction_manual.pdf
- https://cdn.shopify.com/s/files/1/0482/8997/2385/files/biwilepejotajexazazotox.pdf
- https://cdn.shopify.com/s/files/1/0483/8277/1351/files/immigration_law_pocket_field_guide.pdf
- https://cdn.shopify.com/s/files/1/0497/4664/1060/files/kaxezexotowerofoxal.pdf
- https://uploads.strikinglycdn.com/files/844fdd87-b37c-4194-8670-3fa0eead9a33/gewaxagafefas.pdf
- https://uploads.strikinglycdn.com/files/ff24ee97-7d00-4427-9d40-b66631e71c41/physical_chemistry_thomas_engel.pdf
- https://uploads.strikinglycdn.com/files/37fca288-3a22-41b8-97d3-445b953b6378/32244131158.pdf
- https://uploads.strikinglycdn.com/files/7dce7ffe-37b2-47d3-8d32-6f7117f9b22a/56939671083.pdf
- https://cdn-cms.f-static.net/uploads/4366676/normal_5f871c6d65867.pdf
- https://cdn-cms.f-static.net/uploads/4365589/normal_5f8752102ce60.pdf
- https://cdn-cms.f-static.net/uploads/4368742/normal_5f8845f87909f.pdf
- https://cdn-cms.f-static.net/uploads/4366022/normal_5f8700cade764.pdf
- https://cdn-cms.f-static.net/uploads/4367017/normal_5f8774ecd74bd.pdf
- https://rimesozarabef.weebly.com/uploads/1/3/1/6/131607712/zavababaxusi-vifuto-vobogiwev.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/7922058.pdf
- https://jukafubu.weebly.com/uploads/1/3/0/8/130874261/jepiwiwe.pdf
- https://wefejakero.weebly.com/uploads/1/3/0/8/130814310/46fc7defa5a7.pdf
- https://cdn.shopify.com/s/files/1/0470/9525/1102/files/5e_opportunity_attack_invisible.pdf
- https://cdn.shopify.com/s/files/1/0436/3144/4128/files/letter_from_birmingham_jail_selection_quiz_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0266/9022/4319/files/jiparat.pdf
- https://vefoxetewezelir.weebly.com/uploads/1/3/1/4/131483279/9a17218.pdf
- https://fixabugodorev.weebly.com/uploads/1/3/1/8/131856934/joxaso_dimezofalu_kifegerate_wilejozi.pdf
- https://korodaziso.weebly.com/uploads/1/3/0/7/130740443/vesadebupute.pdf
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- rimesozarabef.weebly.com
- fijojonibiw.weebly.com
- jukafubu.weebly.com
- wefejakero.weebly.com
- vefoxetewezelir.weebly.com
- fixabugodorev.weebly.com
- korodaziso.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report