SUSPICIOUS — 81177481238.pdf
SUSPICIOUS — 81177481238.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
12b5ee2d5a4d8f7c88c9cdd5d584caad9b2433f3bd0ff6fb97b56035ff754057 - SHA-1:
11b03a56e27bd5063489b14e5625425b8f03df7e - MD5:
3fb3ea7d68b7482859b325f809d2e921 - ssdeep:
768:yqgGzpDLIIDItHG2/hGm49Hrn7fWI/lfvJ4PGTmXP8E1h3C0F9BECFeIKdMtU33s:KGFnIIovhcL7+x3C4BECUbOw37+qU - TLSH:
T14C339EF314A3EC8C2B8ABB07B9A6015D9149D78D6136A66019C83B2CD47C6FD7F10A51 - Submitted as: 81177481238.pdf
- File type: pdf · Size: 47864 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/3ee57a8e-c2f2-499e-955d-0c1ed806f0b5/45016790798.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=convert+pdf+to+jpg+python+code, https://cdn.shopify.com/s/files/1/0428/8898/6787/files/swtor_powertech_pvp_guide.pdf, https://cdn.shopify.com/s/files/1/0459/7687/9271/files/31967408988.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=convert+pdf+to+jpg+python+code
- https://cdn.shopify.com/s/files/1/0428/8898/6787/files/swtor_powertech_pvp_guide.pdf
- https://cdn.shopify.com/s/files/1/0459/7687/9271/files/31967408988.pdf
- https://cdn.shopify.com/s/files/1/0435/4647/6708/files/oblivion_cheats_xbox_360_duplicate_items.pdf
- https://cdn.shopify.com/s/files/1/0429/5576/7967/files/db2_string_functions_replace.pdf
- https://cdn.shopify.com/s/files/1/0432/8282/5376/files/francis_schaeffer_libros_en_espaol.pdf
- https://cdn.shopify.com/s/files/1/0438/3975/0294/files/www.360_degree_leader.com.pdf
- https://cdn.shopify.com/s/files/1/0467/7812/2393/files/gta_5_mod_apk_for_laptop.pdf
- https://cdn.shopify.com/s/files/1/0486/4078/6590/files/cheats_for_earn_to_die_2.pdf
- https://cdn.shopify.com/s/files/1/0485/0309/5457/files/6564799866.pdf
- https://cdn.shopify.com/s/files/1/0429/6110/9148/files/formula_sheet_for_geometry_eoc.pdf
- https://cdn.shopify.com/s/files/1/0487/8666/9733/files/kapoju.pdf
- https://cdn.shopify.com/s/files/1/0436/4612/4185/files/cross_cable_color_code_rj45.pdf
- https://cdn.shopify.com/s/files/1/0499/5229/3032/files/kt_plan_template.pdf
- https://uploads.strikinglycdn.com/files/3ee57a8e-c2f2-499e-955d-0c1ed806f0b5/45016790798.pdf
- https://uploads.strikinglycdn.com/files/52dd91f7-409b-466a-826a-1f4d421971e4/3343081814.pdf
- https://uploads.strikinglycdn.com/files/21c96721-4527-46c4-a05f-7d51dcdbe9d9/razenefevanuvo.pdf
- https://uploads.strikinglycdn.com/files/8fd53070-8e4a-4d5b-8e85-e12ec53e42ae/63096130015.pdf
- https://uploads.strikinglycdn.com/files/c8414747-f03c-475f-8f97-ff4b1aa8c7b2/fowumoge.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report