SUSPICIOUS — 92f28.pdf
SUSPICIOUS — 92f28.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b8c39f048cca961f792d2a3ea26850ecfb63e57f67294bb9408abd49ad7ab435 - SHA-1:
2c6d382da2c069d2d182bd58fbabc9e63d030ae1 - MD5:
5b6e400e15a5d9644ae47e0a2acb735e - ssdeep:
1536:bGFopu2HCRVrGCZ2BqPfk8hYUVGOBLC5R9R5OsDVnL:6FopDHSV6CMwPDhYrOFC5pIsD9 - TLSH:
T1EE36BFF35057EE4C7A8F5F839DE70199A09AC3886026CB605498672CC4BC7ED7F50A92 - Submitted as: 92f28.pdf
- File type: pdf · Size: 67967 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://jiwadurator.weebly.com/uploads/1/3/0/7/130776405/481408.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=goleman%20emotional%20intelligence%20scale, https://site-1043098.mozfiles.com/files/1043098/winemolezafabafira.pdf, https://site-1041289.mozfiles.com/files/1041289/25115343793.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=goleman%20emotional%20intelligence%20scale
- https://site-1043098.mozfiles.com/files/1043098/winemolezafabafira.pdf
- https://site-1041289.mozfiles.com/files/1041289/25115343793.pdf
- https://site-1037869.mozfiles.com/files/1037869/bovaz.pdf
- https://site-1038497.mozfiles.com/files/1038497/pebuwedakotoka.pdf
- https://site-1038905.mozfiles.com/files/1038905/54614874148.pdf
- https://jiwadurator.weebly.com/uploads/1/3/0/7/130776405/481408.pdf
- https://bibeliki.weebly.com/uploads/1/3/0/7/130738572/7803f03.pdf
- https://jiwepurojal.weebly.com/uploads/1/3/0/7/130775762/lusexaxapel.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/16dfa150.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/5648329.pdf
- https://cdn-cms.f-static.net/uploads/4365542/normal_5f8723f79f9d4.pdf
- https://cdn-cms.f-static.net/uploads/4366628/normal_5f871f71f2162.pdf
- https://uploads.strikinglycdn.com/files/75e3f6fc-5a29-4cc0-9cbc-73195c70d211/10628695366.pdf
- https://uploads.strikinglycdn.com/files/775acf0c-5de8-48cc-b73f-c36c8c0fed69/vegavunosonusaxojurun.pdf
- https://uploads.strikinglycdn.com/files/85d016b9-8ce0-400c-bcbe-f0d8660732e3/bexadupavederafuzikono.pdf
- https://uploads.strikinglycdn.com/files/0dee749f-2927-4433-be8f-e05a715ecf98/wavibu.pdf
- https://uploads.strikinglycdn.com/files/93218ddb-a09a-46f4-b674-cc76f4de048c/72056352383.pdf
- https://site-1039496.mozfiles.com/files/1039496/fusajonimulo.pdf
- https://site-1039329.mozfiles.com/files/1039329/kuzezavede.pdf
- https://site-1048184.mozfiles.com/files/1048184/sion_jungle_guide_s8.pdf
- https://site-1048482.mozfiles.com/files/1048482/vuvelivufivof.pdf
- https://polabufasol.weebly.com/uploads/1/3/2/8/132814050/zawajajafor-rexuzegilel-jolunukojifux.pdf
- https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/tevow.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/kezedivalo-bolumukejufufik.pdf
Embedded domains
- ggtraff.ru
- site-1043098.mozfiles.com
- site-1041289.mozfiles.com
- site-1037869.mozfiles.com
- site-1038497.mozfiles.com
- site-1038905.mozfiles.com
- jiwadurator.weebly.com
- bibeliki.weebly.com
- jiwepurojal.weebly.com
- vozunutav.weebly.com
- fijojonibiw.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1039496.mozfiles.com
- site-1039329.mozfiles.com
- site-1048184.mozfiles.com
- site-1048482.mozfiles.com
- polabufasol.weebly.com
- jaserasozupog.weebly.com
- dimaxafazeza.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report