SUSPICIOUS — 14374820833.pdf
SUSPICIOUS — 14374820833.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1719f38fd28697ff56fc32ec71c157a0ceb6f07dcfe5c138eaf61d62431df521 - SHA-1:
16088a444c482e94a08135d738d18f455a64d391 - MD5:
3ec7379b312b4602a4f104c4cb813eb4 - ssdeep:
768:8gGzpDgAGoKowDfT0eeu5cbB7bw5dn3VljDmjnf0yzR/BB:ZGF0t/6bw5dn3TjDIR/BB - TLSH:
T1A0319EF3549BDD8C7A865B07ADA200A5A489DB883233977058CC7B6CC4FC2FD6E41961 - Submitted as: 14374820833.pdf
- File type: pdf · Size: 40411 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/f86c681c-77d2-45f5-9a2f-1d91a5d5fa4f/gexuwaviwanafu.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=collections+in+java+by+durga+pdf, https://cdn.shopify.com/s/files/1/0462/5639/0295/files/xagilutadadu.pdf, https://cdn.shopify.com/s/files/1/0438/1350/3133/files/english_reading_skills.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=collections+in+java+by+durga+pdf
- https://cdn.shopify.com/s/files/1/0462/5639/0295/files/xagilutadadu.pdf
- https://cdn.shopify.com/s/files/1/0438/1350/3133/files/english_reading_skills.pdf
- https://cdn.shopify.com/s/files/1/0429/8326/0314/files/girls_in_tight_shirts.pdf
- http://zimij.469bce.com/uploads/1/3/0/7/130776208/vuzene_zupekabi.pdf
- http://files.kamachiro.com/uploads/1/3/2/3/132303353/c40fc63afe.pdf
- http://nileni.skiingisbelieving.org/uploads/1/3/1/4/131438379/f90573.pdf
- http://files.ahhs60.org/uploads/1/3/0/7/130739918/2170607.pdf
- http://files.ammoudiclub.com/uploads/1/3/0/7/130739621/bexozisirujevufiti.pdf
- https://uploads.strikinglycdn.com/files/f86c681c-77d2-45f5-9a2f-1d91a5d5fa4f/gexuwaviwanafu.pdf
- https://uploads.strikinglycdn.com/files/e2f95d30-0b89-4204-8749-0cd811d2c2fc/malefakisine.pdf
- https://uploads.strikinglycdn.com/files/e38a02d2-f258-4e5b-84be-230d46d81e35/88748360360.pdf
- https://uploads.strikinglycdn.com/files/c61d82ed-7654-4049-a0a0-01ad9f48e718/kazokakofar.pdf
- http://files.hmrpncc.org/uploads/1/3/1/4/131407469/24fc589b73a.pdf
- http://files.balmdotcalm.net/uploads/1/3/0/8/130814976/6913250.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- zimij.469bce.com
- files.kamachiro.com
- nileni.skiingisbelieving.org
- files.ahhs60.org
- files.ammoudiclub.com
- uploads.strikinglycdn.com
- files.hmrpncc.org
- files.balmdotcalm.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report