SUSPICIOUS — 2133370.pdf
SUSPICIOUS — 2133370.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f39cbdc6604cf41e16fef4d785bbeb274faf6d8ddc3d92ae67c011c275c6f4fb - SHA-1:
bf643baba44063ea3b43e6da949c31245969e5b0 - MD5:
81b9ee1eb58cb98599e9659a961f9b0f - ssdeep:
768:6gGzpDZeKDsZlXNRTSxio+Un+ReBFSJKIVkk8ezaSHjxyQ/WdpRpENcDCxfUeh+E:nGF917VnokU6Q+dpRpieafUm+0GhRo - TLSH:
T110328DF35067FC4C7A8B5F13A9AB106D904AD3886132DAA1499C776CE57C6FE7E10A00 - Submitted as: 2133370.pdf
- File type: pdf · Size: 46002 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/c6e74dff-fe27-4fec-bf38-9f85ee23fdea/xutepiwikipubavegutoz.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=collective%20nouns%20worksheet%20with%20answers%20for%20grade%203, https://uploads.strikinglycdn.com/files/c6e74dff-fe27-4fec-bf38-9f85ee23fdea/xutepiwikipubavegutoz.pdf, https://uploads.strikinglycdn.com/files/2a5dca50-1484-4d58-a1f0-beb2a5f449a7/linear_algebra_5th_edition_by_friedberg_insel_and_spence.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=collective%20nouns%20worksheet%20with%20answers%20for%20grade%203
- https://uploads.strikinglycdn.com/files/c6e74dff-fe27-4fec-bf38-9f85ee23fdea/xutepiwikipubavegutoz.pdf
- https://uploads.strikinglycdn.com/files/2a5dca50-1484-4d58-a1f0-beb2a5f449a7/linear_algebra_5th_edition_by_friedberg_insel_and_spence.pdf
- https://uploads.strikinglycdn.com/files/e8f23303-ccde-49bb-b57e-45200375180f/tefag.pdf
- https://uploads.strikinglycdn.com/files/9e4e8a0f-0a72-40f1-a4e2-dc155250c006/wujizexipifunilagepefif.pdf
- https://s3.amazonaws.com/henghuili-files2/31130949349.pdf
- https://cdn.shopify.com/s/files/1/0268/8670/1256/files/70985749519.pdf
- https://cdn.shopify.com/s/files/1/0434/1245/5591/files/vefelubituwuvidokeg.pdf
- https://cdn.shopify.com/s/files/1/0430/6563/9073/files/15514985245.pdf
- https://cdn.shopify.com/s/files/1/0495/5134/3768/files/92878952476.pdf
- https://cdn.shopify.com/s/files/1/0437/2060/5850/files/wow_heirloom_gear_ironforge.pdf
- https://cdn.shopify.com/s/files/1/0483/8250/9213/files/sheila_maid_clothes_airer_instructions.pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/3934721782.pdf
- https://cdn.shopify.com/s/files/1/0457/7551/9910/files/lord_of_the_rings_ebook_free_download_kindle.pdf
- https://cdn.shopify.com/s/files/1/0428/4655/2227/files/69035408011.pdf
- https://cdn.shopify.com/s/files/1/0431/4418/3974/files/18688060509.pdf
- https://cdn.shopify.com/s/files/1/0502/2810/1304/files/94779570818.pdf
- https://cdn.shopify.com/s/files/1/0435/7236/3432/files/vocabu_lit_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0266/9087/9667/files/nokobomesegevega.pdf
- https://cdn.shopify.com/s/files/1/0481/3874/8071/files/critical_theory_today_tyson.pdf
- https://cdn.shopify.com/s/files/1/0431/2737/3981/files/international_creative_management_literary_agents.pdf
- https://cdn.shopify.com/s/files/1/0503/8309/3910/files/vodefugar.pdf
- https://cdn.shopify.com/s/files/1/0499/4246/2618/files/jufifixu.pdf
- https://cdn.shopify.com/s/files/1/0432/3213/3278/files/thats_so_fetch_quote.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report