SUSPICIOUS — 4114545575.pdf
SUSPICIOUS — 4114545575.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0defe79f5327e9a055d1612ba228634aeb281d08d78f30d95eb958d7bc97f44b - SHA-1:
43d5eaf98e22c5e60a66e0bb8a426bb6e42356c8 - MD5:
a383c17cbd476cebc7c6fb913849be38 - ssdeep:
768:3gGzpDoOESu5X5KesFV7LbNUzOVNQ7Oyas6+Ug2a20xUR:QGF8rJ5pp8xyasCZ0xUR - TLSH:
T1E2329EF32067DE9C7ACA6B03AEA61059759AD38A6122D7A015C8773CC4FC6ED3F10950 - Submitted as: 4114545575.pdf
- File type: pdf · Size: 45894 bytes
- Verdict: suspicious (58/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://files.grindfitnesstn.com/uploads/1/3/2/7/132740763/1039662.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=much+ado+about+nothing+essay+topics, https://cdn.shopify.com/s/files/1/0437/0294/3899/files/rajoxofozukuwefeguzodopem.pdf, https://cdn.shopify.com/s/files/1/0483/7903/5808/files/fuxizavasuvix.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=much+ado+about+nothing+essay+topics
- https://cdn.shopify.com/s/files/1/0437/0294/3899/files/rajoxofozukuwefeguzodopem.pdf
- https://cdn.shopify.com/s/files/1/0483/7903/5808/files/fuxizavasuvix.pdf
- https://cdn.shopify.com/s/files/1/0434/2982/2625/files/jolinulaposo.pdf
- https://uploads.strikinglycdn.com/files/eb039263-af6a-47f5-8676-27a4b8034a9f/jolamuforedarunevax.pdf
- https://uploads.strikinglycdn.com/files/767b42d0-6495-4404-a18b-2ee867c8dd59/2370974120.pdf
- https://uploads.strikinglycdn.com/files/83cc6234-ae7d-4747-b517-a6f1673389a1/58162076689.pdf
- https://uploads.strikinglycdn.com/files/4e4cb659-0e2e-489a-be65-a8fa610fbad7/7438208043.pdf
- http://files.grindfitnesstn.com/uploads/1/3/2/7/132740763/1039662.pdf
- http://files.ksyee.com/uploads/1/3/0/8/130815351/7289062.pdf
- http://xirujolak.stmarkslutheranfargo.com/uploads/1/3/0/7/130776485/2757700.pdf
- http://nininoni.nunes-ueno.com/uploads/1/3/1/4/131407089/relijagigujeja-gubov-tirarubiriwuwo-jifir.pdf
- https://uploads.strikinglycdn.com/files/3ce396db-67a8-418d-9096-7dfddbabcc57/togujusapa.pdf
- https://uploads.strikinglycdn.com/files/3f6c1517-1ac9-41aa-8edd-a195644eb6d9/vitumisetekezixafab.pdf
- https://uploads.strikinglycdn.com/files/8f54ef5a-650c-4f8d-99ac-0b88b6358bb1/56213840968.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- files.grindfitnesstn.com
- files.ksyee.com
- xirujolak.stmarkslutheranfargo.com
- nininoni.nunes-ueno.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report