SUSPICIOUS — 172d90d7531b.pdf
SUSPICIOUS — 172d90d7531b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
cb8370de5b314fd80e75420ac76f802cef17d87e390002b1b6ea7f78e045a515 - SHA-1:
bad91d992c8d0fddcf58d63a88aa888a96767f0a - MD5:
325dfafff3396a3d455e686ba3a7814e - ssdeep:
768:GgGzpDVlYoWz5kmDxRjxufgfOZK/1xCmHI3jjbTBZV6cH15ixm/SAdbbz3QMq:TGFZlYoejo4mZK/1AiITTx6cH15ixmK9 - TLSH:
T1B3339EF35097EE8C7AC78F876DB62168608AD3887033A39044C8B77CC5B85AD6F15961 - Submitted as: 172d90d7531b.pdf
- File type: pdf · Size: 47991 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://moxitasa.weebly.com/uploads/1/3/1/4/131454719/waxegof_vipowe_javidosekepod.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=importancia%20de%20la%20calidad%20ambiental%20pdf, https://uploads.strikinglycdn.com/files/4b159ef9-5237-4248-9574-8f1be9987929/affidavit_of_residency.pdf, https://uploads.strikinglycdn.com/files/dd938859-0f97-496e-b407-03ab03600f28/bizhub_pro_920_driver.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=importancia%20de%20la%20calidad%20ambiental%20pdf
- https://uploads.strikinglycdn.com/files/4b159ef9-5237-4248-9574-8f1be9987929/affidavit_of_residency.pdf
- https://uploads.strikinglycdn.com/files/dd938859-0f97-496e-b407-03ab03600f28/bizhub_pro_920_driver.pdf
- https://uploads.strikinglycdn.com/files/e925095e-74bc-400f-91a2-5fd7d06b2345/lijozilofebira.pdf
- https://uploads.strikinglycdn.com/files/b6c52390-dc00-49e3-887a-0cfe640375cb/calorie_king_book_2017.pdf
- https://walijogopabo.weebly.com/uploads/1/3/0/7/130776167/b4e6966cf639ec.pdf
- https://s3.amazonaws.com/magapeguwabe/mufeboriwukevaxonowemenuf.pdf
- https://uploads.strikinglycdn.com/files/cf7f9d77-a2d4-48cc-b019-7683fec9d5c1/forklift_training_powerpoint.pdf
- https://s3.amazonaws.com/bopuxosavubare/the_practice_of_statistics_5th_edition_free_download.pdf
- https://s3.amazonaws.com/piwupevivotixi/agonist_and_antagonist_drugs.pdf
- https://s3.amazonaws.com/ganubifirigevi/assainissement_urbain_cours.pdf
- https://zoxamadafipezo.weebly.com/uploads/1/3/1/1/131164297/luwojovuj.pdf
- https://s3.amazonaws.com/jufowokedunod/guremiwalapub.pdf
- https://moxitasa.weebly.com/uploads/1/3/1/4/131454719/waxegof_vipowe_javidosekepod.pdf
- https://cdn-cms.f-static.net/uploads/4383571/normal_5f8fe95320eb3.pdf
- https://cdn-cms.f-static.net/uploads/4365575/normal_5f91015e64711.pdf
- https://uploads.strikinglycdn.com/files/a152b01f-2a55-4ea0-abf8-2a77e2c422e3/52160873175.pdf
- https://s3.amazonaws.com/gixawetopoli/25443150521.pdf
- https://cdn-cms.f-static.net/uploads/4383571/normal_5f9a08772ab4b.pdf
- https://uploads.strikinglycdn.com/files/071386d3-e67a-45c6-aa1c-90876f4fa42b/mulberry_fork_wma.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- walijogopabo.weebly.com
- s3.amazonaws.com
- zoxamadafipezo.weebly.com
- moxitasa.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report