SUSPICIOUS — 17911589212.pdf
SUSPICIOUS — 17911589212.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
17e6ff93f96c419c602e5d77bbde41f9df616dc59173d981af653bd6fbe10a97 - SHA-1:
39814d37e5663f325c2f9ddf862fae09e988a210 - MD5:
a3b05f55786a680f11e62ba683f7419f - ssdeep:
1536:jGFZLbHYy8ICJK9BSS28LhXuN1sMgRk0iz:yFZLbYy82gS28Eowx - TLSH:
T1BE34BFF710A7DC8C7A8B6B039FAB11996186D3CC213697645888B67CD07C6FD7E00A61 - Submitted as: 17911589212.pdf
- File type: pdf · Size: 54037 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://files.barryapplefestival.com/uploads/1/3/1/8/131871710/fokisu.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=mw2+free+multiplayer+download+pc, http://kagapa.mastropiece.com/uploads/1/3/2/6/132681647/jubelubetibo-suzebu-gudekerud-risabamuto.pdf, http://files.peacoquette.com/uploads/1/3/1/6/131636764/sejutozawutisabo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=mw2+free+multiplayer+download+pc
- http://kagapa.mastropiece.com/uploads/1/3/2/6/132681647/jubelubetibo-suzebu-gudekerud-risabamuto.pdf
- http://files.peacoquette.com/uploads/1/3/1/6/131636764/sejutozawutisabo.pdf
- http://files.barryapplefestival.com/uploads/1/3/1/8/131871710/fokisu.pdf
- http://nutuki.wingsopen.com/uploads/1/3/1/4/131406515/pumejumebu.pdf
- https://uploads.strikinglycdn.com/files/755f8c21-4d0f-49d1-8d57-f46545d1a33a/bepokilerekokorukarima.pdf
- https://uploads.strikinglycdn.com/files/d990b9ba-3acd-4d30-899b-b7b0d4b4166c/guwum.pdf
- https://uploads.strikinglycdn.com/files/ad8348bc-5d55-49e3-b171-8369dff2894c/70317621522.pdf
- https://uploads.strikinglycdn.com/files/3985cfd3-186b-46b8-a74d-2316316f490f/zapalofamuxemofizili.pdf
- http://files.lifepathchurch.org/uploads/1/3/1/1/131164249/8204296.pdf
- http://rimifip.montrealmusiciansexchange.com/uploads/1/3/1/4/131483603/toluximo.pdf
- http://xolalurez.course.amsterdam/uploads/1/3/1/4/131407386/xubukupon.pdf
- http://files.imagesstratford.com/uploads/1/3/2/3/132303209/doguv.pdf
- http://files.frankm-arts.studio/uploads/1/3/0/7/130738603/f67a97.pdf
- https://uploads.strikinglycdn.com/files/30186e61-b39b-4508-b257-2e5d6f74adab/mexunibalugobi.pdf
- https://uploads.strikinglycdn.com/files/cf432866-2fae-4661-ab0c-f074ce4423b7/80898076004.pdf
- https://uploads.strikinglycdn.com/files/159a4b05-0f7a-45a1-bbd3-f53da6ace0a2/nowagotewikoketufok.pdf
- https://uploads.strikinglycdn.com/files/c17130af-80a0-48f4-8ec1-59055100310b/fakevuxubodufudupa.pdf
- https://uploads.strikinglycdn.com/files/fbca3b32-7dd3-41c5-a30c-d8fbd10e2d9e/lajiwijixa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- kagapa.mastropiece.com
- files.peacoquette.com
- files.barryapplefestival.com
- nutuki.wingsopen.com
- uploads.strikinglycdn.com
- files.lifepathchurch.org
- rimifip.montrealmusiciansexchange.com
- files.imagesstratford.com
- www.w3.org
- purl.org
- ns.adobe.com
- xolalurez.course.amsterdam
- files.frankm-arts.studio
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report