SUSPICIOUS — 46466209251.pdf
SUSPICIOUS — 46466209251.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0e840ab90eea059bea347fc00b12a56e85f06408394ee038d3312b7e10a00cd2 - SHA-1:
a77fb21d654cabc73b034f6b1706637ce3a3e66b - MD5:
3fa1e01e02dbc345a00dcf48c8a2bafd - ssdeep:
768:BNgGzpDkp9pP569Xspt3DvvOZ3YcyxO8e0OZa9PneAR8G7F6QhQ:BuGF4p99RWZIcYOJ0OZYpR8Gx6QhQ - TLSH:
T12E314BF310A7ED4C7687AF036EEE285D9189D7889172E7604588272DC4BC77D7E10A60 - Submitted as: 46466209251.pdf
- File type: pdf · Size: 41472 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/801600ee-19ae-4e3a-be36-30a6b6209f81/rivebarufabalefi.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=rowenta+turbo+silence+fan+assembly+instructions, https://site-1039651.mozfiles.com/files/1039651/wapuviwib.pdf, https://site-1042968.mozfiles.com/files/1042968/daiwa_fishing_catalog_2020.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=rowenta+turbo+silence+fan+assembly+instructions
- https://site-1039651.mozfiles.com/files/1039651/wapuviwib.pdf
- https://site-1042968.mozfiles.com/files/1042968/daiwa_fishing_catalog_2020.pdf
- https://site-1044496.mozfiles.com/files/1044496/37866994204.pdf
- https://site-1038367.mozfiles.com/files/1038367/gugigofuxadikigifuku.pdf
- https://uploads.strikinglycdn.com/files/b0dafa2a-9744-41ac-a57e-7daf969d8def/gedufok.pdf
- https://uploads.strikinglycdn.com/files/00441585-58b0-4888-a1e9-e747a518c4f0/manegos.pdf
- https://uploads.strikinglycdn.com/files/f2807455-d7df-4a77-85ab-aa48d9922f70/fipin.pdf
- https://uploads.strikinglycdn.com/files/801600ee-19ae-4e3a-be36-30a6b6209f81/rivebarufabalefi.pdf
- https://uploads.strikinglycdn.com/files/a51549b3-26f5-47e7-92db-fa4499f9d767/lagir.pdf
- https://uploads.strikinglycdn.com/files/2cab2c3b-a8a3-4a9d-91ea-b16595b7249e/12492984024.pdf
- https://uploads.strikinglycdn.com/files/685a62c9-8aea-4d33-8910-9cc8c41d3ea3/39293053819.pdf
- https://uploads.strikinglycdn.com/files/bc3246cf-6531-4c0f-b24d-b9cf742a3d95/61597814452.pdf
- https://uploads.strikinglycdn.com/files/8758b61b-89c9-4578-809e-5394076ff72a/38934333332.pdf
- https://cdn.shopify.com/s/files/1/0504/8238/0965/files/pentaho_data_integration_manual.pdf
- https://cdn.shopify.com/s/files/1/0437/5488/1175/files/mamamox.pdf
- https://cdn.shopify.com/s/files/1/0437/3735/0296/files/cuisinart_extreme_brew_carafe.pdf
- https://cdn.shopify.com/s/files/1/0434/3886/6593/files/to_be_continued_filter_instagram.pdf
- https://cdn.shopify.com/s/files/1/0494/1378/3719/files/statutory_law_includes_state_statutes.pdf
- https://cdn.shopify.com/s/files/1/0483/1117/3275/files/animators_survival_kit.pdf
- https://cdn.shopify.com/s/files/1/0479/4309/0332/files/spiral_knights_piercing_swords.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/debizikirapanas.pdf
- https://lupolaluxu.weebly.com/uploads/1/3/2/6/132681144/f320f.pdf
- https://xuvakaxatal.weebly.com/uploads/1/3/1/0/131070170/lujiwuzov.pdf
- https://jezaxegare.weebly.com/uploads/1/3/1/3/131380636/8169730.pdf
Embedded domains
- cctraff.ru
- site-1039651.mozfiles.com
- site-1042968.mozfiles.com
- site-1044496.mozfiles.com
- site-1038367.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- vuxozajuje.weebly.com
- lupolaluxu.weebly.com
- xuvakaxatal.weebly.com
- jezaxegare.weebly.com
- jonukejunuxesa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report