SUSPICIOUS — 45667199983.pdf
SUSPICIOUS — 45667199983.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
23fe32c27e72a312909e7520986aba0d1a148e35e124260280fa49967ca85e14 - SHA-1:
3f5a4b903c29d9263febf08066c083b015249e7e - MD5:
8eadb26ba9548c2ce8846c6ef70a836b - ssdeep:
768:/XgGzpDyvJyEKGr7wvNEe3KjCTQPrESJwaCbv1xWJ1Ejure1zk1YjPNUc879U+4M:/wGFmvge5jn6JJE1Cure1zk1v7UnG05W - TLSH:
T1C632AFF711B7DD8D7A8EAB07BDFA0058558A87482133A960159C3B7CC4B8AFD6E10950 - Submitted as: 45667199983.pdf
- File type: pdf · Size: 46819 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/16d08172-951f-42d1-a603-6a239f3f81b1/jedafawenovoxa.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=mathrubhumi+calendar+september+2019+pdf, https://cdn.shopify.com/s/files/1/0428/9835/8432/files/dosoxuwananeworatimuk.pdf, https://cdn.shopify.com/s/files/1/0429/6271/4773/files/audiovisual_definition.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=mathrubhumi+calendar+september+2019+pdf
- https://cdn.shopify.com/s/files/1/0428/9835/8432/files/dosoxuwananeworatimuk.pdf
- https://cdn.shopify.com/s/files/1/0429/6271/4773/files/audiovisual_definition.pdf
- https://cdn.shopify.com/s/files/1/0433/8604/4570/files/2624935407.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/27347714529.pdf
- https://cdn.shopify.com/s/files/1/0437/0182/9797/files/rakivoj.pdf
- https://cdn.shopify.com/s/files/1/0431/4267/6636/files/cantoral_catolico_partituras.pdf
- https://cdn.shopify.com/s/files/1/0434/2104/0792/files/tevuzatozaso.pdf
- http://vedov.dash-hounds.co.uk/uploads/1/3/2/6/132681513/kawar.pdf
- http://files.lisamedoffdesigns.com/uploads/1/3/0/7/130739802/8049702.pdf
- https://uploads.strikinglycdn.com/files/16d08172-951f-42d1-a603-6a239f3f81b1/jedafawenovoxa.pdf
- https://uploads.strikinglycdn.com/files/25c9833c-080b-4d3d-9b20-1367fbe37eb2/88667554149.pdf
- https://uploads.strikinglycdn.com/files/5bcdb063-8a19-4693-a12d-cf2f503b13a0/fanaropiresubisag.pdf
- https://uploads.strikinglycdn.com/files/4843a267-abbf-4942-a3ec-1b0247541b25/76129758388.pdf
- http://bltlly.com/15sbro
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- vedov.dash-hounds.co.uk
- files.lisamedoffdesigns.com
- uploads.strikinglycdn.com
- bltlly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report