SUSPICIOUS — 6695333.pdf
SUSPICIOUS — 6695333.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
dcf5046270ffdf09916ad51ddf9bc1274f1fb69827869a960ea5ec97ef1c4571 - SHA-1:
a537b57e432973d566ad0a3025a21d57f6278058 - MD5:
7eed230e55401e61d0e57b0168993e14 - ssdeep:
768:92gGzpDBadldVJ+KQifEFp1FZKyWgGOD5l7FHQkfMWnw46zJ7:RGFFex+Ziwp1z+gXjFHnMWn36zJ7 - TLSH:
T179329EF350A7DDD87B87AF03AAA6209D6206874C3032967419CD772DC87C6BCAD45A60 - Submitted as: 6695333.pdf
- File type: pdf · Size: 43354 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/3ab08f6a-e10d-4105-89b0-806ac69b59c0/assessment_guide_houghton_mifflin_grade_5_answer_key.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=western%20union%20bug, https://uploads.strikinglycdn.com/files/3ab08f6a-e10d-4105-89b0-806ac69b59c0/assessment_guide_houghton_mifflin_grade_5_answer_key.pdf, https://uploads.strikinglycdn.com/files/f23a9f43-95b7-4ea4-9ba5-7b24cc97d6a8/66794409344.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=western%20union%20bug
- https://s3.amazonaws.com/ladojenefe/subaru_levorg_sti_horsepower.pdf
- https://uploads.strikinglycdn.com/files/3ab08f6a-e10d-4105-89b0-806ac69b59c0/assessment_guide_houghton_mifflin_grade_5_answer_key.pdf
- https://uploads.strikinglycdn.com/files/f23a9f43-95b7-4ea4-9ba5-7b24cc97d6a8/66794409344.pdf
- https://nawowelefet.weebly.com/uploads/1/3/4/4/134498780/9401032.pdf
- https://uploads.strikinglycdn.com/files/ca143198-44e2-45fa-b671-1b17db73d84d/lurapowobitibebazopok.pdf
- https://genamimiwovem.weebly.com/uploads/1/3/1/6/131636881/newibuwo_sebabamijosup_naxuruvebiwina.pdf
- https://kesevaze.weebly.com/uploads/1/3/1/3/131383297/mubabuxud-luwobof-xexoton-nowaxanowekevin.pdf
- https://uploads.strikinglycdn.com/files/713386f6-b40b-4a49-a498-82e939863e41/45988195835.pdf
- https://uploads.strikinglycdn.com/files/ec9132b8-6e66-4624-a5d6-0eab2d7abe2f/arduino_buzzer_circuit.pdf
- https://uploads.strikinglycdn.com/files/212ac789-1da2-4ec4-8dab-f1ebf34b4699/dorunowivakubobi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- nawowelefet.weebly.com
- genamimiwovem.weebly.com
- kesevaze.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report