SUSPICIOUS — 40325929880.pdf
SUSPICIOUS — 40325929880.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0423dea8f196eede3b934ea53c9568f2879cb05eb38350473b99eec97892e2d8 - SHA-1:
e4eafae3302fb8bd30317df835403c3582e1c7d8 - MD5:
e1249fea57e05724e0c0dab8fc044a29 - ssdeep:
768:tgGzpDKLNhHmjmTOOQGV4IuEpu500HBxnN4JrC8BklNo8o443b4q4Qt3:OGFGJLRQf55hxnN4Jr7BSo8o443b4q46 - TLSH:
T102319DF75197DC8C3A4AAB036EA72168524AD78C613697A045CC772CC4BC6FE6F00E60 - Submitted as: 40325929880.pdf
- File type: pdf · Size: 40431 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/7c0a7d53-bda3-4e51-a3fc-adeb1d898a2b/53678889629.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=present+simple+affirmative+exercises+pdf+elementary, https://uploads.strikinglycdn.com/files/995cf573-16ba-446f-948a-53eb5e610d23/paresodewuzitejub.pdf, https://uploads.strikinglycdn.com/files/7c0a7d53-bda3-4e51-a3fc-adeb1d898a2b/53678889629.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=present+simple+affirmative+exercises+pdf+elementary
- https://uploads.strikinglycdn.com/files/995cf573-16ba-446f-948a-53eb5e610d23/paresodewuzitejub.pdf
- https://uploads.strikinglycdn.com/files/7c0a7d53-bda3-4e51-a3fc-adeb1d898a2b/53678889629.pdf
- https://uploads.strikinglycdn.com/files/432561b3-c40b-4464-bb74-5ed97604a7d8/3202849687.pdf
- https://uploads.strikinglycdn.com/files/1151c49d-f642-40a2-98cb-09d11bbe9f0b/89396348444.pdf
- https://uploads.strikinglycdn.com/files/67991706-8da4-4c45-b1d6-baf4b1aedac0/zevawetukikawitujiwebiz.pdf
- https://uploads.strikinglycdn.com/files/80504cab-ceda-4aeb-adda-f6af0c4ef04e/76067971531.pdf
- https://uploads.strikinglycdn.com/files/864a7c17-dd4f-4798-8ee0-f78a13374aa5/98096734906.pdf
- https://uploads.strikinglycdn.com/files/61b71d40-ef52-4ac8-b612-074724aad359/nobigago.pdf
- https://uploads.strikinglycdn.com/files/53d6bee3-bdbf-40ea-ab5d-4f38f1047080/sivuma.pdf
- https://uploads.strikinglycdn.com/files/51687aec-d672-49a9-8912-3358a2a954d9/21624247503.pdf
- https://cdn.shopify.com/s/files/1/0440/4707/3445/files/imprimir_curp_nuevo_formato_oaxaca.pdf
- https://cdn.shopify.com/s/files/1/0429/7120/1695/files/nudiwegimovakotoset.pdf
- https://cdn.shopify.com/s/files/1/0428/1021/2518/files/tirofafivupev.pdf
- https://cdn.shopify.com/s/files/1/0450/6501/1352/files/holland_code_questionnaire.pdf
- https://cdn.shopify.com/s/files/1/0472/3143/4917/files/erfolgreich_verhandeln.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report