SUSPICIOUS — 62813889561.pdf
SUSPICIOUS — 62813889561.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0ff7f50e6589516e76d20b4229e1fa3be8b9082e976dee3ba2d739a967c5877c - SHA-1:
fea78e0319c3bf96fe8e0aa8d596e06eb6e05bb8 - MD5:
2d2781b0f21ecf22706a8ca2064b7728 - ssdeep:
768:qxgGzpDGVNSpiwPRx+iLfOCWMEBoq38ekkSgHLs+aw+/bz:pGF6w1LHlzqsekkzHiw+/bz - TLSH:
T136319FF311A7ED4C7A8A7F036EA2116DA54AD7486033D6A0098C377DD4BC6BE7E00661 - Submitted as: 62813889561.pdf
- File type: pdf · Size: 43155 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/797dee79-b569-45ba-9be7-9ece8f607022/46013391065.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=cell+phone+signal+jammer+android+app, https://cdn.shopify.com/s/files/1/0436/5287/4390/files/snc_cs3_home.pdf, https://cdn.shopify.com/s/files/1/0499/4682/0776/files/fgo_tv_tropes_avenger.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=cell+phone+signal+jammer+android+app
- https://cdn.shopify.com/s/files/1/0436/5287/4390/files/snc_cs3_home.pdf
- https://cdn.shopify.com/s/files/1/0499/4682/0776/files/fgo_tv_tropes_avenger.pdf
- https://cdn.shopify.com/s/files/1/0437/8548/6498/files/lewemovebibovemofadi.pdf
- https://cdn.shopify.com/s/files/1/0428/5209/0022/files/kemimoto_rzr_door_bags.pdf
- https://uploads.strikinglycdn.com/files/c4a8ab88-7a41-4583-9d30-a98ad4b1a305/bopiw.pdf
- https://uploads.strikinglycdn.com/files/91bbe490-6d14-42ef-b22b-8f0401465b4a/61385308262.pdf
- https://uploads.strikinglycdn.com/files/d91a8b44-6228-450b-838f-ccd78705363f/22728601161.pdf
- https://uploads.strikinglycdn.com/files/ab6b9234-e2c1-4868-81a8-d23923b299da/23826218351.pdf
- http://fadoner.leslieslanguage.com/uploads/1/3/1/3/131379958/ecf0ca.pdf
- http://mesapu.tomsbait.com/uploads/1/3/1/4/131437987/monosemexava.pdf
- http://files.eastcoastschoolofsafety.com/uploads/1/3/1/3/131383476/40ee3ba6de23bb.pdf
- http://files.cricketmanpress.com/uploads/1/3/0/7/130776861/fujuvitajosamuruw.pdf
- https://uploads.strikinglycdn.com/files/797dee79-b569-45ba-9be7-9ece8f607022/46013391065.pdf
- https://uploads.strikinglycdn.com/files/aa4dc2e2-49e5-4788-adb1-d0048bee8f83/wulevufabusese.pdf
- https://uploads.strikinglycdn.com/files/3c9cce61-c8c0-4213-af59-e0bdc575294f/pazubilaj.pdf
- https://uploads.strikinglycdn.com/files/dae4ff44-0e87-4766-9e61-f4deb26b25b2/60312769670.pdf
- https://uploads.strikinglycdn.com/files/91e48462-978c-43f7-b693-91caab567f4c/25862296458.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- fadoner.leslieslanguage.com
- mesapu.tomsbait.com
- files.eastcoastschoolofsafety.com
- files.cricketmanpress.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report