SUSPICIOUS — 27365588436.pdf
SUSPICIOUS — 27365588436.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d8b88b30c31e8c9a8027aedd115445d8e1131f07c9c0b9ffe27d5db38bc0bcd6 - SHA-1:
a0c80446cda1ce02b010f5138ed8eaad46d2573f - MD5:
810a697885a325806631ac4a051b5d55 - ssdeep:
3072:aFNp8Y95sPzG91ZPAU6jtEjpaJt7ejUkgoCUV9tPNK3LwwFqLd7V:qvvHZljp1lgdUVL43ih - TLSH:
T19B3DE1F310BBED4CA987EB076DE9249D548AD74D9073CB20909C272DD47CABD6E44A20 - Submitted as: 27365588436.pdf
- File type: pdf · Size: 129492 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/d7a27dfe-3cd1-4089-b306-2b7d39bbb8ae/74341322969.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=computer+application+notes+pdf+for+b.com, https://uploads.strikinglycdn.com/files/d7a27dfe-3cd1-4089-b306-2b7d39bbb8ae/74341322969.pdf, https://uploads.strikinglycdn.com/files/aad65da5-e771-4c9b-88b4-2c2dfa3549c1/sutedajewupude.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=computer+application+notes+pdf+for+b.com
- https://uploads.strikinglycdn.com/files/d7a27dfe-3cd1-4089-b306-2b7d39bbb8ae/74341322969.pdf
- https://uploads.strikinglycdn.com/files/aad65da5-e771-4c9b-88b4-2c2dfa3549c1/sutedajewupude.pdf
- https://uploads.strikinglycdn.com/files/471697f2-6692-4b07-b121-44175facbb0f/24690708995.pdf
- https://uploads.strikinglycdn.com/files/72fc3ddc-cdfa-420f-a6f4-9929098ff9e2/47400225960.pdf
- https://uploads.strikinglycdn.com/files/f3573208-4a28-4c7a-a7a7-49756328192c/mumepezug.pdf
- https://cdn-cms.f-static.net/uploads/4366331/normal_5f8713a00d682.pdf
- https://cdn-cms.f-static.net/uploads/4366003/normal_5f870bf384461.pdf
- https://cdn-cms.f-static.net/uploads/4365619/normal_5f8715ef8fc19.pdf
- https://cdn-cms.f-static.net/uploads/4366048/normal_5f86f9722771d.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/3794757.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/xenemavurinap_jokepirewiteda_fijalezej_gemewije.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/dozafawegikuxoto.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/fibawubaxavuvabu.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/4102594.pdf
- https://site-1043580.mozfiles.com/files/1043580/rajivomedusuk.pdf
- https://site-1042922.mozfiles.com/files/1042922/92946440608.pdf
- https://site-1040288.mozfiles.com/files/1040288/kusedukuwitodivaf.pdf
- https://site-1043357.mozfiles.com/files/1043357/63915278775.pdf
- https://site-1039743.mozfiles.com/files/1039743/59131159313.pdf
- https://site-1044151.mozfiles.com/files/1044151/kunidilofokufo.pdf
- https://site-1042539.mozfiles.com/files/1042539/wulefen.pdf
- https://site-1042187.mozfiles.com/files/1042187/32179695962.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- b.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- bedizegoresupa.weebly.com
- vuxozajuje.weebly.com
- keniwuki.weebly.com
- mogilifus.weebly.com
- site-1043580.mozfiles.com
- site-1042922.mozfiles.com
- site-1040288.mozfiles.com
- site-1043357.mozfiles.com
- site-1039743.mozfiles.com
- site-1044151.mozfiles.com
- site-1042539.mozfiles.com
- site-1042187.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report