SUSPICIOUS — 789489.pdf
SUSPICIOUS — 789489.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f5a575a2da951277135dbf0de88972d753d367061985fb33ff4a1f6a6dafb88d - SHA-1:
f61ba46dde7b595b9cf27af1f89b1a5944165b98 - MD5:
7e2de5596d5c61a9828a33e098156939 - ssdeep:
1536:7GFdTTyT9Mi8LfY8a6JIIEibnLE6KpBAUWdYKfZ6W:aFdve918Lfs6BEibn1KpKplN - TLSH:
T13634AEF350D7DD8CBA8B5B4398A711B86099D388723297908588BA7CD57C97D7F00E60 - Submitted as: 789489.pdf
- File type: pdf · Size: 56887 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://fomomeku.weebly.com/uploads/1/3/2/7/132712435/3546827.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=cohetes%20de%20agua%20pdf, https://cdn.shopify.com/s/files/1/0497/8940/3290/files/zebojijoromotoxegu.pdf, https://cdn.shopify.com/s/files/1/0432/1456/9640/files/46586659939.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=cohetes%20de%20agua%20pdf
- https://cdn.shopify.com/s/files/1/0497/8940/3290/files/zebojijoromotoxegu.pdf
- https://cdn.shopify.com/s/files/1/0432/1456/9640/files/46586659939.pdf
- https://cdn.shopify.com/s/files/1/0498/4035/7538/files/complete_physics_for_cambridge_igcse_revision_guide.pdf
- https://cdn.shopify.com/s/files/1/0502/8406/9049/files/letterland_bouncy_ben_worksheets.pdf
- https://cdn.shopify.com/s/files/1/0501/0613/8787/files/41667645971.pdf
- https://fomomeku.weebly.com/uploads/1/3/2/7/132712435/3546827.pdf
- https://kutenamig.weebly.com/uploads/1/3/0/7/130740069/ac86b2b.pdf
- https://kafasomawupi.weebly.com/uploads/1/3/0/7/130775431/9750844.pdf
- https://sokuvotaboraj.weebly.com/uploads/1/3/0/7/130776263/vopadowiganuwop.pdf
- https://putigazabikikim.weebly.com/uploads/1/3/2/6/132682718/a95e175bcf.pdf
- https://uploads.strikinglycdn.com/files/1e6eb7d9-aa84-4695-8d87-2d645d753bb7/ziwifo.pdf
- https://uploads.strikinglycdn.com/files/3ecbed4f-63f8-4c97-af3e-8fb4ffe09447/19029565117.pdf
- https://uploads.strikinglycdn.com/files/b4b5d033-f9c8-4fdb-b684-4d29b51da196/zojeno.pdf
- https://uploads.strikinglycdn.com/files/609f0a1b-8864-403c-98c4-0f51f8e28338/lipogekatukovixubufogas.pdf
- https://uploads.strikinglycdn.com/files/156b12f7-9508-4d45-a5e7-5db729a88d68/41068019792.pdf
- https://uploads.strikinglycdn.com/files/f3b5339d-204e-4224-83e7-e4930b7b5b2b/79176288748.pdf
- https://uploads.strikinglycdn.com/files/2b492192-07b8-41d5-b892-a0b95a24051e/8461917559.pdf
- https://cdn-cms.f-static.net/uploads/4366339/normal_5f8722c73343b.pdf
- https://cdn-cms.f-static.net/uploads/4368782/normal_5f890bda0b1f5.pdf
- https://cdn-cms.f-static.net/uploads/4369760/normal_5f88db9d76218.pdf
- https://cdn-cms.f-static.net/uploads/4372100/normal_5f8edbf7e2a1b.pdf
- https://cdn-cms.f-static.net/uploads/4377674/normal_5f92a9cfaa0a1.pdf
- https://s3.amazonaws.com/leguvefu/zidij.pdf
- https://s3.amazonaws.com/gupuso/52383035930.pdf
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- fomomeku.weebly.com
- kutenamig.weebly.com
- kafasomawupi.weebly.com
- sokuvotaboraj.weebly.com
- putigazabikikim.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report