SUSPICIOUS — 73350043193.pdf
SUSPICIOUS — 73350043193.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0a3212901ce52d697d2b1fabe1da5cfdedcb9d6675412c5f6d15cb9a279e626e - SHA-1:
eed0a8b2d583f49b6a284dcff6883d9883b22770 - MD5:
44324031c97d1bf7a319d494ded56c20 - ssdeep:
768:1gGzpDDptZ3ZzWrlmcFBdVmkgxoamBYLgEXSgLh0vGn93s2u:mGFPp2vJ6oVEigLh0A93s2u - TLSH:
T19F32AEF3289BDD8C7A8BAB07B9B71451105AD78C2222E750158C376CC4BC7BE7E506A0 - Submitted as: 73350043193.pdf
- File type: pdf · Size: 47258 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/5285ffc0-7392-47ca-a8d0-70b371f76883/redekofazubonizibutole.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=differentiated+classroom+instructional+strategies, https://uploads.strikinglycdn.com/files/5285ffc0-7392-47ca-a8d0-70b371f76883/redekofazubonizibutole.pdf, https://uploads.strikinglycdn.com/files/e9af2779-bf1f-4189-bff2-8e4d43094118/nuzatekimelavusi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=differentiated+classroom+instructional+strategies
- https://uploads.strikinglycdn.com/files/5285ffc0-7392-47ca-a8d0-70b371f76883/redekofazubonizibutole.pdf
- https://uploads.strikinglycdn.com/files/e9af2779-bf1f-4189-bff2-8e4d43094118/nuzatekimelavusi.pdf
- https://uploads.strikinglycdn.com/files/cf84ade3-ea67-480b-b9d5-61f49d66bc7f/94071719503.pdf
- https://uploads.strikinglycdn.com/files/50d9d37b-172e-4016-9463-3a97a7a509c0/3931066951.pdf
- https://uploads.strikinglycdn.com/files/47f5b4d1-023c-46e1-a07b-45e80e976865/83050433036.pdf
- https://cdn.shopify.com/s/files/1/0438/3123/0614/files/learn_how_to_fly_a_plane.pdf
- https://cdn.shopify.com/s/files/1/0486/1866/8192/files/gimitunesabajalunojalemet.pdf
- https://cdn.shopify.com/s/files/1/0432/7096/3366/files/solaparemuretogurezebo.pdf
- https://cdn.shopify.com/s/files/1/0477/6303/0172/files/papas_freezeria_apk_download.pdf
- https://uploads.strikinglycdn.com/files/ce6abea6-0cb5-4937-94b4-97e443fb38e6/38625543337.pdf
- https://uploads.strikinglycdn.com/files/b7dee58d-d7fc-4025-b653-fbeb46a66f20/mipizitalabifaxe.pdf
- https://uploads.strikinglycdn.com/files/fcd3d2a0-c2b2-443e-a635-7863048c2f97/xadotuweposijiz.pdf
- https://uploads.strikinglycdn.com/files/b285a0fd-700c-4caa-8b92-e72ca05d7150/kusotufe.pdf
- https://uploads.strikinglycdn.com/files/1ae5cc60-2b6c-4cfa-93e4-0d51cf1ae1ed/bevofexax.pdf
- https://uploads.strikinglycdn.com/files/98ea14fc-6f7a-49ee-906b-2b845682355a/selonepapitaranawoza.pdf
- https://uploads.strikinglycdn.com/files/0dc85e81-19d7-4fba-b5af-93eb2e5a7055/jusakodirowa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report