SUSPICIOUS — 49499681674.pdf
SUSPICIOUS — 49499681674.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
27a3c9286cb5bcd9f7923270c103986c5bfba43c633c13cb0b5423acaefafc53 - SHA-1:
dc42f02060cfa6193b25bfdb0b55a9159c58e07c - MD5:
acca711155190613f7dfdaf6837ec7b0 - ssdeep:
768:ogGzpDsdm61aFpQ7AtA4akPMwc8uYXELnu57fC/OfRngGZKT7:lGF4dz1aFp3A4akPMw9X+nuhjfRng0M7 - TLSH:
T10F319EF391ABCE8C3E82BB076DE614496149C78C2172D7A0558C7B2DD4782FC6F21962 - Submitted as: 49499681674.pdf
- File type: pdf · Size: 41906 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/a9407bc7-391c-4319-88e5-a301cf40e47c/87356000479.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=probability+density+function+example+problems+pdf, https://uploads.strikinglycdn.com/files/a9407bc7-391c-4319-88e5-a301cf40e47c/87356000479.pdf, https://uploads.strikinglycdn.com/files/cd71d474-217f-464c-be2a-eb49f68240fe/dafebodu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=probability+density+function+example+problems+pdf
- https://uploads.strikinglycdn.com/files/a9407bc7-391c-4319-88e5-a301cf40e47c/87356000479.pdf
- https://uploads.strikinglycdn.com/files/cd71d474-217f-464c-be2a-eb49f68240fe/dafebodu.pdf
- https://uploads.strikinglycdn.com/files/9b5ee511-5f1b-48c9-9cbf-d30231e57ccf/85796956247.pdf
- https://uploads.strikinglycdn.com/files/37f51afd-f36e-49d1-9ecc-ac5c441f7734/58994955639.pdf
- https://site-1036945.mozfiles.com/files/1036945/badokorafufawivewulopozef.pdf
- https://site-1036939.mozfiles.com/files/1036939/kipokikulasomupozirudu.pdf
- https://site-1039413.mozfiles.com/files/1039413/4186014988.pdf
- https://site-1036936.mozfiles.com/files/1036936/vunelunebojolugokunij.pdf
- https://site-1036680.mozfiles.com/files/1036680/94881230400.pdf
- https://uploads.strikinglycdn.com/files/4e964e08-5a0e-4c43-9636-bfeecaca42d4/93375496173.pdf
- https://uploads.strikinglycdn.com/files/e27844ad-464a-47a3-8541-6a746e637d97/xixogugedebukamerozezo.pdf
- https://uploads.strikinglycdn.com/files/a7d7f3f4-1fbd-454f-bf60-9aaadc9b464b/vopuwokosekusemanifesoger.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1036945.mozfiles.com
- site-1036939.mozfiles.com
- site-1039413.mozfiles.com
- site-1036936.mozfiles.com
- site-1036680.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report