SUSPICIOUS — 51662200691.pdf
SUSPICIOUS — 51662200691.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
02035f7a6d6df17e97b9ad704e584ed8510be9879b95a7dae3a20e06749f1d99 - SHA-1:
b14932afad5cf7a7b2e3b1810fab8d052a373471 - MD5:
29d213ca30027b7e98e1818acc380cb9 - ssdeep:
768:DgGzpDp8ar3aLgj6Ho93ZnIVu52DlUUwhLv7MlAlmoi:8GFlpa0j6Ho93VINuUOLv1lmoi - TLSH:
T13532AFF350ABDD8C6A86DB03AEAE281D5145D3886122AB7414D8772CC8BC37D7F40E61 - Submitted as: 51662200691.pdf
- File type: pdf · Size: 47397 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/723a3bd3-2a4f-43d8-ad24-efac7946a776/79878766627.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=api+developer+guide+salesforce, https://uploads.strikinglycdn.com/files/723a3bd3-2a4f-43d8-ad24-efac7946a776/79878766627.pdf, https://uploads.strikinglycdn.com/files/fc11727c-e24c-4d4e-a4f9-98b1d935c7ed/3785272313.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=api+developer+guide+salesforce
- https://uploads.strikinglycdn.com/files/723a3bd3-2a4f-43d8-ad24-efac7946a776/79878766627.pdf
- https://uploads.strikinglycdn.com/files/fc11727c-e24c-4d4e-a4f9-98b1d935c7ed/3785272313.pdf
- https://uploads.strikinglycdn.com/files/cbcf7949-1929-4589-9fc9-cfd796afd548/mawer.pdf
- https://uploads.strikinglycdn.com/files/2c04cdb9-67d9-46b5-bea9-068a70dcc7d7/fabimutesifuvexosofesev.pdf
- https://site-1039728.mozfiles.com/files/1039728/18462932691.pdf
- https://site-1037864.mozfiles.com/files/1037864/48101290067.pdf
- https://site-1040180.mozfiles.com/files/1040180/sitolijitituraweju.pdf
- https://site-1039400.mozfiles.com/files/1039400/detovolibisuvip.pdf
- https://uploads.strikinglycdn.com/files/bba0fd32-e551-4ff6-badd-cc031ab59d58/58894108291.pdf
- https://uploads.strikinglycdn.com/files/d27a2b8c-1b77-4995-bcce-3a453da87cfd/42547296175.pdf
- https://uploads.strikinglycdn.com/files/be3ee91e-8a0b-48e1-850f-bfa847b1eb03/xemitazegivalabamil.pdf
- https://uploads.strikinglycdn.com/files/4b6f2334-2b3a-4b62-8738-6da26daaf916/xofikin.pdf
- http://defeporub.thrivedesignconsulting.ca/uploads/1/3/1/4/131410818/5690569.pdf
- http://files.kraftfahrer-vermittlung.com/uploads/1/3/0/9/130969997/78a2ba06b00ac.pdf
- http://files.mullanroadproject.com/uploads/1/3/0/8/130874223/dd2e110dbc295.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1039728.mozfiles.com
- site-1037864.mozfiles.com
- site-1040180.mozfiles.com
- site-1039400.mozfiles.com
- defeporub.thrivedesignconsulting.ca
- files.kraftfahrer-vermittlung.com
- files.mullanroadproject.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report