SUSPICIOUS — nezelaka.pdf
SUSPICIOUS — nezelaka.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
cf2aa463bf9a75d983b864876b6228c6ef31d357deee68d9e5b9d2e2a3279abd - SHA-1:
3286f1d4ef86de98267f88de2994558b2f3af7ae - MD5:
235a5709d272f04ecdf21a37c49c5ea2 - ssdeep:
768:sgGzpDmZUn5kAd4tlF87kpdLsf1SnaA98iz5xNL9t2guhTAzgMlSyWx:pGFapLH+6a6cguhglSyWx - TLSH:
T1C7329EF350A7EC8C7A8B9B039DAB105A9589C38DA137E76009D87B3DC4BC1BD6E10551 - Submitted as: nezelaka.pdf
- File type: pdf · Size: 46180 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/ca580195-b4f7-4127-b9b5-906bc2dc8673/jemaxivisupamabuv.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=mcculloch%20eager%20beaver%202014%20chainsaw%20manual, https://uploads.strikinglycdn.com/files/ca580195-b4f7-4127-b9b5-906bc2dc8673/jemaxivisupamabuv.pdf, https://uploads.strikinglycdn.com/files/ad314ac9-3b41-41fc-8a6a-62f9d9dff662/six_thermodynamic_states_of_the_same_monatomic_ideal_gas_sample_are_represented_in_the_figure.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=mcculloch%20eager%20beaver%202014%20chainsaw%20manual
- https://uploads.strikinglycdn.com/files/ca580195-b4f7-4127-b9b5-906bc2dc8673/jemaxivisupamabuv.pdf
- https://uploads.strikinglycdn.com/files/ad314ac9-3b41-41fc-8a6a-62f9d9dff662/six_thermodynamic_states_of_the_same_monatomic_ideal_gas_sample_are_represented_in_the_figure.pdf
- https://uploads.strikinglycdn.com/files/11f11118-24ce-4965-9ed8-71dd36531109/10763403950.pdf
- https://uploads.strikinglycdn.com/files/bcb5f758-6a8f-4cbd-a4d7-095f47d3618c/sotod.pdf
- https://cdn.shopify.com/s/files/1/0503/6651/3312/files/game_night_word_whizzle_answers.pdf
- https://cdn.shopify.com/s/files/1/0436/1994/2563/files/76026852832.pdf
- https://cdn.shopify.com/s/files/1/0440/7354/9974/files/foy_h_moody_high_school_corpus_christi_tx.pdf
- https://fexejolimoti.weebly.com/uploads/1/3/4/1/134131812/lukonuwasopoju.pdf
- https://voxapinave.weebly.com/uploads/1/3/2/7/132740917/kotojekatez.pdf
- https://dikoriwapajok.weebly.com/uploads/1/3/4/4/134447187/a37436b47.pdf
- https://cdn.shopify.com/s/files/1/0498/8341/4682/files/23669863454.pdf
- https://cdn.shopify.com/s/files/1/0486/4062/2760/files/vipenupovixikunel.pdf
- https://cdn.shopify.com/s/files/1/0433/6759/6191/files/loader_droid_apk_latest_version.pdf
- https://cdn.shopify.com/s/files/1/0467/7756/5337/files/zatowazuximejowifodesele.pdf
- https://uploads.strikinglycdn.com/files/d2a28e88-43b7-4417-a91f-c65ef7d1a07e/97843356089.pdf
- https://uploads.strikinglycdn.com/files/2b23aa5f-5d6e-404d-8a00-471fe5d79c30/3856793031.pdf
- https://uploads.strikinglycdn.com/files/3c6a6136-dcc6-4b65-af9c-8af6901f192e/54062073875.pdf
- https://uploads.strikinglycdn.com/files/ba8c0bed-a09f-4847-b3e4-52ca789b576d/watch_mission_impossible_rogue_natio.pdf
- https://s3.amazonaws.com/leguvefu/duties_of_sales_engineer.pdf
- https://s3.amazonaws.com/zirojopemup/4025307164.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- fexejolimoti.weebly.com
- voxapinave.weebly.com
- dikoriwapajok.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report