SUSPICIOUS — 94330752356.pdf
SUSPICIOUS — 94330752356.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
16617177b3cdb4ddb6bf95cad3a147872ba123220bb678f8ae3988ba3b8d615d - SHA-1:
d2c4c58b170d53a078aaa03c8e9f63d8722fba1c - MD5:
03bca51838472b7abb3fb24b44d6d635 - ssdeep:
768:KgGzpDH0ohe/WMGHkepapHBgfqTWLLYnI2xsMtaz:XGFb0ztOkqadBgfqSfYI2xsMtaz - TLSH:
T182339EF300A3EECC3E8B6F535EAB1599518A9289B133A65019D87B6CC4BC5FC6F10911 - Submitted as: 94330752356.pdf
- File type: pdf · Size: 48916 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://files.christchurchchichester.com/uploads/1/3/1/4/131452840/2883c5b34481.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=techniques+de+traduction+anglais+francais+pdf, http://files.christchurchchichester.com/uploads/1/3/1/4/131452840/2883c5b34481.pdf, http://files.talisman48.com/uploads/1/3/0/9/130969080/663855.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=techniques+de+traduction+anglais+francais+pdf
- http://files.christchurchchichester.com/uploads/1/3/1/4/131452840/2883c5b34481.pdf
- http://files.talisman48.com/uploads/1/3/0/9/130969080/663855.pdf
- http://maliv.biblerapsnation.com/uploads/1/3/1/6/131606968/jetaganesusasexa.pdf
- http://mitotu.jacksongirlssoccer.com/uploads/1/3/1/6/131606186/979399.pdf
- http://bofex.kilroymusic.com/uploads/1/3/1/4/131409090/nogilozolidoso.pdf
- http://files.kirstikristiansen.com/uploads/1/3/2/7/132712099/pagezetanadovagufo.pdf
- http://jasujorur.dyslexicdoughnut.com/uploads/1/3/1/3/131378985/5808609.pdf
- https://uploads.strikinglycdn.com/files/fa6d13a9-6a8d-4d32-8b43-bdeffbe8ca42/61243912281.pdf
- https://uploads.strikinglycdn.com/files/d3241f58-d465-447f-a381-1ff42c751a4d/siloloxum.pdf
- https://uploads.strikinglycdn.com/files/890a880f-ff88-4ed8-8bc8-a9069ff906cb/1535564572.pdf
- https://uploads.strikinglycdn.com/files/8a864383-0afa-489f-8222-c5771affce4f/dupuzulumafavuvefunonawub.pdf
- https://uploads.strikinglycdn.com/files/a12e4406-e8a5-485f-8e1e-b0045d10f24a/paluxugevob.pdf
- https://site-1036960.mozfiles.com/files/1036960/sevekixenepeve.pdf
- https://site-1037033.mozfiles.com/files/1037033/94131158519.pdf
- https://site-1039147.mozfiles.com/files/1039147/70092335381.pdf
- https://site-1039765.mozfiles.com/files/1039765/95949158334.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- files.christchurchchichester.com
- files.talisman48.com
- maliv.biblerapsnation.com
- mitotu.jacksongirlssoccer.com
- bofex.kilroymusic.com
- files.kirstikristiansen.com
- jasujorur.dyslexicdoughnut.com
- uploads.strikinglycdn.com
- site-1036960.mozfiles.com
- site-1037033.mozfiles.com
- site-1039147.mozfiles.com
- site-1039765.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report