SUSPICIOUS — 99026432179.pdf
SUSPICIOUS — 99026432179.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
02af1c0fd534f9f5ed6309ac331a601b097a829b056436dcf9d8d6ea3ea6b699 - SHA-1:
cd7ad63a352f92f7694026b5d573913b9abdceaa - MD5:
a6e02c46f0fe2c003adb28184363245a - ssdeep:
1536:RGFpvXv32YYYwIRYPijWdf2RWmKjrBK3:0FpvXv3JtYkWd+fAs - TLSH:
T1FE34AFF31097DD8C77CAAB476DB615699099C34CA132E350888CB72DC57CAAD7E20D21 - Submitted as: 99026432179.pdf
- File type: pdf · Size: 55355 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/8e415cff-a798-4377-9082-1004caf85d0b/parigibudufemeto.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=vex+4+unblocked+games+google+sites, https://uploads.strikinglycdn.com/files/8e415cff-a798-4377-9082-1004caf85d0b/parigibudufemeto.pdf, https://cdn-cms.f-static.net/uploads/4365626/normal_5f988987cbe4d.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=vex+4+unblocked+games+google+sites
- https://s3.amazonaws.com/ribowexulo/encyclopedia_judaica_vol_9.pdf
- https://uploads.strikinglycdn.com/files/8e415cff-a798-4377-9082-1004caf85d0b/parigibudufemeto.pdf
- https://s3.amazonaws.com/zasepo/xorigelixidebajefitorip.pdf
- https://s3.amazonaws.com/debamijizozexo/stillwater_area_high_school_calendar.pdf
- https://s3.amazonaws.com/zetare/lobamegoka.pdf
- https://s3.amazonaws.com/dixaleko/jk_bank_po_syllabus_2019.pdf
- https://cdn-cms.f-static.net/uploads/4365626/normal_5f988987cbe4d.pdf
- https://uploads.strikinglycdn.com/files/cc0045b0-5097-4dcf-9f8b-93d9f99d32db/1826235593.pdf
- https://cdn-cms.f-static.net/uploads/4366965/normal_5f9750633457a.pdf
- https://cdn.shopify.com/s/files/1/0483/4525/2003/files/revinulujurix.pdf
- https://uploads.strikinglycdn.com/files/928afa23-434c-4ccf-9429-4b494eee952e/attack_on_titan_season_1_episode_16.pdf
- https://cdn.shopify.com/s/files/1/0434/5289/1298/files/rivap.pdf
- https://cdn.shopify.com/s/files/1/0429/6690/9081/files/mafulezol.pdf
- https://cdn.shopify.com/s/files/1/0497/5008/1690/files/38158653528.pdf
- https://cdn.shopify.com/s/files/1/0432/0185/5646/files/oracle_application_express_installation_guide_11g.pdf
- https://cdn.shopify.com/s/files/1/0501/8147/2416/files/ricette_per_pentola_a_pressione.pdf
- https://uploads.strikinglycdn.com/files/af1b83ee-3be8-49a6-90a0-1245e2298b8a/laxalewonoju.pdf
- https://cdn-cms.f-static.net/uploads/4380867/normal_5f91598a91358.pdf
- https://cdn.shopify.com/s/files/1/0499/3227/1770/files/kawerunujisuvalewufuz.pdf
- https://ruxodinari.weebly.com/uploads/1/3/4/3/134377607/mokumi_lawopas.pdf
- https://wuwotozon.weebly.com/uploads/1/3/4/3/134315251/xudiwifabubufa_jesokar_tupivusajexu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- ruxodinari.weebly.com
- wuwotozon.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report