SUSPICIOUS — 79448986394.pdf
SUSPICIOUS — 79448986394.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
21f5c304cefb72649194f61c38dc175f4de82cb4b1c205991dd4c2bdb9b1e74a - SHA-1:
3053414219767a1d3efb5427822f44319c323646 - MD5:
700e3d9b2763c0a8faf1501c1bcbe861 - ssdeep:
768:egGzpDOC1FG/hkVNSFo9jneEqRHEovY8vIFrbfh9NHbNrn:bGFCbDFIeEq1pqt9t9n - TLSH:
T1B9319EF351ABED4C368B6F03ADB7115D510AE6496132ABA0448C3B3CC4B87FD6E11A61 - Submitted as: 79448986394.pdf
- File type: pdf · Size: 42989 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/62b3e5df-1533-41b9-8818-90f8e3cc29b3/jowujamatojanodu.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=catia+v5+part+design+tutorial+pdf, https://uploads.strikinglycdn.com/files/62b3e5df-1533-41b9-8818-90f8e3cc29b3/jowujamatojanodu.pdf, https://uploads.strikinglycdn.com/files/b583f2b9-bf8c-484a-8527-97a08b8e6b3a/ferudimafuserunomilitas.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=catia+v5+part+design+tutorial+pdf
- https://uploads.strikinglycdn.com/files/62b3e5df-1533-41b9-8818-90f8e3cc29b3/jowujamatojanodu.pdf
- https://uploads.strikinglycdn.com/files/b583f2b9-bf8c-484a-8527-97a08b8e6b3a/ferudimafuserunomilitas.pdf
- https://uploads.strikinglycdn.com/files/baace5db-19db-40c7-8f70-28818ce770d4/degadavera.pdf
- https://uploads.strikinglycdn.com/files/a02c1482-e425-4299-ae80-d02800512d92/nanowiluwabuzojal.pdf
- https://uploads.strikinglycdn.com/files/b7cdefae-233c-4fd2-9075-3f774d6f3229/vigugonapuzu.pdf
- https://cdn.shopify.com/s/files/1/0480/3035/1519/files/flappy_golf_2_recruit_codes.pdf
- https://cdn.shopify.com/s/files/1/0428/5458/0390/files/dovanisezugunima.pdf
- https://cdn.shopify.com/s/files/1/0481/3851/8681/files/zijuman.pdf
- https://cdn.shopify.com/s/files/1/0432/3111/7467/files/beginner_bodybuilding_workout.pdf
- https://cdn.shopify.com/s/files/1/0482/9170/9092/files/rodney_atkins_cleaning_this_gun_come_on_in_boy_lyrics.pdf
- http://movufomub.briarcreeksportsmanclub.com/uploads/1/3/0/8/130873782/4384884.pdf
- http://files.contewesthills.net/uploads/1/3/1/3/131383860/xuvilu.pdf
- http://files.gourmazingcuisine.com/uploads/1/3/0/8/130813855/jasudutigomabi-pujufot-vubudapum.pdf
- http://wizok.victoriawindowwashing.ca/uploads/1/3/1/1/131164293/c4b8d081c7d.pdf
- http://sezuliz.priscilajamison.com/uploads/1/3/0/9/130969663/fbe44993d1.pdf
- https://uploads.strikinglycdn.com/files/10207951-47de-4dac-9919-58d50695d7cc/tugawibopasirubepudebaz.pdf
- https://uploads.strikinglycdn.com/files/5a52e99e-071b-4c3c-b716-5073716c2831/gesexawutovagewanuzoz.pdf
- https://uploads.strikinglycdn.com/files/8ee11af3-8bb4-4baf-badc-6ea277c1e66a/tudanufuwukozaloxizelom.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- movufomub.briarcreeksportsmanclub.com
- files.contewesthills.net
- files.gourmazingcuisine.com
- wizok.victoriawindowwashing.ca
- sezuliz.priscilajamison.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report