SUSPICIOUS — 73c84dbbb526.pdf
SUSPICIOUS — 73c84dbbb526.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fc62b95ad4cf0df3de167493e4b729a6b3ffd3d246d1e3d3923a9608bcd3df6a - SHA-1:
a15a07ceeb784702bd3d024e64c2fb82fd1a0892 - MD5:
9ac4914e3768b555daf47904e32c2dc3 - ssdeep:
768:ugGzpDwfHhRxgRqDCZ7/Eyh9ujTKIG6y+ql5KiBezo3SMV6W4qb4z1:LGF0f9GqDCSdjZly+ql5g6SMV6JBz1 - TLSH:
T142329EF300A7DC4C6A8A9B07EDA715E96189934C6137975008987B3DC5BC2BE7E50CA2 - Submitted as: 73c84dbbb526.pdf
- File type: pdf · Size: 45703 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/39cdcb01-0283-4aeb-8667-6f2c1f6f7f37/11646006566.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=page%20layout%20tab%20pdf, https://uploads.strikinglycdn.com/files/39cdcb01-0283-4aeb-8667-6f2c1f6f7f37/11646006566.pdf, https://uploads.strikinglycdn.com/files/49cef79c-882a-41e3-942a-e94637161b8f/zakujifodekife.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=page%20layout%20tab%20pdf
- https://s3.amazonaws.com/zirojopemup/bibusakakonut.pdf
- https://s3.amazonaws.com/baxadelefofibuz/catolicismo_romano_loraine_boettner.pdf
- https://s3.amazonaws.com/gewisetug/caderno_caligrafia_para_imprimir.pdf
- https://s3.amazonaws.com/tadovu/materiales_metalicos_ferrosos.pdf
- https://uploads.strikinglycdn.com/files/39cdcb01-0283-4aeb-8667-6f2c1f6f7f37/11646006566.pdf
- https://uploads.strikinglycdn.com/files/49cef79c-882a-41e3-942a-e94637161b8f/zakujifodekife.pdf
- https://nigokozop.weebly.com/uploads/1/3/4/4/134436215/f4bd997d.pdf
- https://polabufasol.weebly.com/uploads/1/3/2/8/132814050/jedilaluwisolufurila.pdf
- https://wetuxabo.weebly.com/uploads/1/3/0/8/130873937/42137.pdf
- https://wanezetisozol.weebly.com/uploads/1/3/4/4/134468493/b942a04a249df69.pdf
- https://wekubuzebebam.weebly.com/uploads/1/3/0/7/130739705/nikoxowo_jufiwozamaradig_lodebu_perusafimu.pdf
- https://uploads.strikinglycdn.com/files/289668f4-6415-49eb-becb-be19a72fe318/84681858170.pdf
- https://uploads.strikinglycdn.com/files/296c13a9-7808-46e1-92cb-9b2d6989167d/71442004672.pdf
- https://uploads.strikinglycdn.com/files/e66d406d-060f-4303-8118-25ecb56f0aca/tiginufef.pdf
- https://uploads.strikinglycdn.com/files/26a90623-e40d-4cd6-8cde-1378abf35dc3/16512021667.pdf
- https://uploads.strikinglycdn.com/files/71c6f4f8-f41c-4030-a50d-ab2f2bcf659a/tuwimuzedap.pdf
- https://netaluzubik.weebly.com/uploads/1/3/0/8/130813777/e5b66c9657af.pdf
- https://wosezobar.weebly.com/uploads/1/3/1/8/131856012/0b53da6ac.pdf
- https://tedumuwoke.weebly.com/uploads/1/3/1/3/131397970/fedakujejalimu-zitesowodizo.pdf
- https://rosikotukixaru.weebly.com/uploads/1/3/4/3/134312973/lalova-zemab-dilitilusiw.pdf
- https://s3.amazonaws.com/tetazino/ghatna_chakra_gs_book_in_english.pdf
- https://s3.amazonaws.com/henghuili-files/87986497257.pdf
- https://s3.amazonaws.com/fasanag/28205051227.pdf
- https://s3.amazonaws.com/fofeguj/gofozijom.pdf
Embedded domains
- ggtraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- nigokozop.weebly.com
- polabufasol.weebly.com
- wetuxabo.weebly.com
- wanezetisozol.weebly.com
- wekubuzebebam.weebly.com
- netaluzubik.weebly.com
- wosezobar.weebly.com
- tedumuwoke.weebly.com
- rosikotukixaru.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report