SUSPICIOUS — ee07088.pdf
SUSPICIOUS — ee07088.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d5948b73a8037964e8a2733b94d10c05da78b721117bf6cf7bdeba6caa1745d1 - SHA-1:
ee5d6c0980e611f7f9aab38423498da0496464ac - MD5:
b2738756b8bc9064aaf497c24c40f586 - ssdeep:
768:N5gGzpDZ4pMJDOSu494xqEhT2AZ1odyaIaWD1+XGKNJcqpS/6hnhoI:EGFl4puDulhqPdyaIND1+1N98myI - TLSH:
T194318CF310A7DD8C7D879B43ADBA1589604AC388712797A45998776CC8BC2BCBF10871 - Submitted as: ee07088.pdf
- File type: pdf · Size: 41867 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://kinojapi.weebly.com/uploads/1/3/2/3/132302846/temerawaf.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=value%20proposition%20design%20pdf%20espa%C3%B1ol, https://kinojapi.weebly.com/uploads/1/3/2/3/132302846/temerawaf.pdf, https://leruzifu.weebly.com/uploads/1/3/2/3/132302941/binolukagixozemoba.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=value%20proposition%20design%20pdf%20espa%C3%B1ol
- https://kinojapi.weebly.com/uploads/1/3/2/3/132302846/temerawaf.pdf
- https://leruzifu.weebly.com/uploads/1/3/2/3/132302941/binolukagixozemoba.pdf
- https://vonolorijamitef.weebly.com/uploads/1/3/4/4/134452045/8303072.pdf
- https://sirawomaperuli.weebly.com/uploads/1/3/1/3/131398091/8486a8d.pdf
- https://fivilogavizizov.weebly.com/uploads/1/3/4/4/134446089/4045890.pdf
- https://s3.amazonaws.com/kavitokolezub/musabegalokafatep.pdf
- https://s3.amazonaws.com/gupuso/46459957952.pdf
- https://s3.amazonaws.com/subud/xovuk.pdf
- https://s3.amazonaws.com/sugaguxagu/firosovuxomuzoz.pdf
- https://s3.amazonaws.com/subud/napigunoriseborazajoxitik.pdf
- https://cdn.shopify.com/s/files/1/0492/1579/9462/files/bantu_migration_map.pdf
- https://cdn.shopify.com/s/files/1/0437/6035/3429/files/evil_eye_plus_apk.pdf
- https://uploads.strikinglycdn.com/files/77e33461-6c79-426f-b029-bd6f233a4c03/gujixa.pdf
- https://uploads.strikinglycdn.com/files/f2188bc5-abc1-4da4-94c5-7cd13486d820/41760677471.pdf
- https://uploads.strikinglycdn.com/files/b7815bf9-503a-419c-ab19-2c3e70141362/dreams_and_inward_journeys_8th_editi.pdf
- https://uploads.strikinglycdn.com/files/65237a55-bd76-415d-a6e1-2f90cdebee34/30570717772.pdf
- https://uploads.strikinglycdn.com/files/5fd5aa5e-fe0d-4692-acc2-2a4e233e89a7/52265923317.pdf
- https://uploads.strikinglycdn.com/files/5a64a5dc-760b-4abd-942f-ae3f1ed3bdbd/paxuz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- kinojapi.weebly.com
- leruzifu.weebly.com
- vonolorijamitef.weebly.com
- sirawomaperuli.weebly.com
- fivilogavizizov.weebly.com
- s3.amazonaws.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report