SUSPICIOUS — 74261780793.pdf
SUSPICIOUS — 74261780793.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
16d140622240755b1a903cf06e71b2fc3d9e6c7a59c08f2b1b26b47c151cef69 - SHA-1:
f4879269ec1f76cbc901500d2ae33388169b287a - MD5:
5609f29702e86171d17cc33178b386d1 - ssdeep:
768:dgGzpDZMuaN6YeDFDPvejxwu2yTFEposn/kl+xDFlW3G2b2X2hF2hh2NT:eGF1kTIvpHxqsn9xDFlMTb2GhAh0NT - TLSH:
T11333AEF3559BDD8C6E8BAF83ADA21144609AC7883137AB6014C87BBDC5781BD7F50920 - Submitted as: 74261780793.pdf
- File type: pdf · Size: 48980 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/28b10bdf-22f3-4c8b-aad6-7a47b514a5b2/13342456957.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=propiedades+quimicas+del+bicarbonato+de+sodio, https://uploads.strikinglycdn.com/files/28b10bdf-22f3-4c8b-aad6-7a47b514a5b2/13342456957.pdf, https://uploads.strikinglycdn.com/files/b0bfe6b7-1225-4c69-92c6-48af133b4b86/20817977100.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=propiedades+quimicas+del+bicarbonato+de+sodio
- https://uploads.strikinglycdn.com/files/28b10bdf-22f3-4c8b-aad6-7a47b514a5b2/13342456957.pdf
- https://uploads.strikinglycdn.com/files/b0bfe6b7-1225-4c69-92c6-48af133b4b86/20817977100.pdf
- https://uploads.strikinglycdn.com/files/7f773e54-fa66-4e0a-b739-5fa8410d0ab3/89783370389.pdf
- https://uploads.strikinglycdn.com/files/af294e59-1180-43d8-82bf-f59da0775e04/bivixazajatusorififipaga.pdf
- https://uploads.strikinglycdn.com/files/9a29244b-c798-4b5f-8f77-c4d7387c189e/84933625500.pdf
- http://ketator.heritagefloristcortland.com/uploads/1/3/1/4/131453558/6172085.pdf
- https://site-1037009.mozfiles.com/files/1037009/lekililobifajuz.pdf
- https://site-1037135.mozfiles.com/files/1037135/22965113609.pdf
- https://site-1043408.mozfiles.com/files/1043408/jorafagidatu.pdf
- https://site-1036753.mozfiles.com/files/1036753/66877687376.pdf
- https://site-1038482.mozfiles.com/files/1038482/86283943444.pdf
- https://uploads.strikinglycdn.com/files/f3c6870f-1e7c-4a4b-b803-76a15cd57940/piwamul.pdf
- https://uploads.strikinglycdn.com/files/1dc9eaf4-d183-4e13-8502-b0ef9f68dd9e/1910974511.pdf
- https://uploads.strikinglycdn.com/files/a399fae8-e1af-4237-af9a-207090534532/julewujigegipiwusosu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- ketator.heritagefloristcortland.com
- site-1037009.mozfiles.com
- site-1037135.mozfiles.com
- site-1043408.mozfiles.com
- site-1036753.mozfiles.com
- site-1038482.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report