SUSPICIOUS — 16769728243.pdf
SUSPICIOUS — 16769728243.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
285923e0a7899879f8b8815215c285c9dd6b08ea5ce8778509a96ddf277958ea - SHA-1:
6bdb54151980864ade531430268e17d8b3565818 - MD5:
a899d08865397ea13923ebce14d7bebc - ssdeep:
768:gxgGzpDSpofGUj4IZjf8RKYymi5UbXbOQoz3bsFhL2EAvpAl0uyRWHOb53ffSBsV:7GFepTx6fQ/ydhbNG/ygHOb5AsrZ - TLSH:
T109339FF350A7ED8C76C7AB036EBA34695049EA8C64369664548C772CC4FC2BD3F41A50 - Submitted as: 16769728243.pdf
- File type: pdf · Size: 50552 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/ce9df12f-4cc5-40f8-88d2-0c0b9165a51b/rinoxutipidirejuv.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=cara+disable+adblock+di+chrome+android, https://uploads.strikinglycdn.com/files/ce9df12f-4cc5-40f8-88d2-0c0b9165a51b/rinoxutipidirejuv.pdf, https://uploads.strikinglycdn.com/files/f6ef3bd6-8b94-43a7-ab4c-402311331ad7/xisom.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=cara+disable+adblock+di+chrome+android
- https://uploads.strikinglycdn.com/files/ce9df12f-4cc5-40f8-88d2-0c0b9165a51b/rinoxutipidirejuv.pdf
- https://uploads.strikinglycdn.com/files/f6ef3bd6-8b94-43a7-ab4c-402311331ad7/xisom.pdf
- https://uploads.strikinglycdn.com/files/f22f793c-b137-4f72-8109-e86fa4d40ec3/61396852578.pdf
- https://uploads.strikinglycdn.com/files/1b1d3932-eb68-4f37-8c90-ffc026c8d137/bigipa.pdf
- https://uploads.strikinglycdn.com/files/89752877-96aa-43c3-93a6-387db335013b/2402523144.pdf
- https://cdn-cms.f-static.net/uploads/4367005/normal_5f874ef2a1db0.pdf
- https://cdn-cms.f-static.net/uploads/4366376/normal_5f875114416e8.pdf
- https://cdn-cms.f-static.net/uploads/4367299/normal_5f8753f218930.pdf
- https://cdn-cms.f-static.net/uploads/4366339/normal_5f872240d084a.pdf
- https://cdn-cms.f-static.net/uploads/4365608/normal_5f874616062f3.pdf
- https://rivisoni.weebly.com/uploads/1/3/0/7/130739016/xesisoberarugeporere.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/vevumisomus-ditukuwazapom-joveba-begibenura.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/gevoderovepiru.pdf
- https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/da0366c694e301c.pdf
- https://rakamukomegu.weebly.com/uploads/1/3/2/6/132681656/438e071b43ca.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/roriturosiw.pdf
- https://jumuwubugunitus.weebly.com/uploads/1/3/1/0/131070493/4b8c57f23e76d7d.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f87143010545.pdf
- https://cdn-cms.f-static.net/uploads/4365598/normal_5f87090738e37.pdf
- https://cdn-cms.f-static.net/uploads/4365598/normal_5f874ebd85f1f.pdf
- https://povutepumik.weebly.com/uploads/1/3/2/7/132741486/poralizetugit.pdf
- https://jukafubu.weebly.com/uploads/1/3/0/8/130874261/nodelorofe_ritizolomireku_gavefava_jafilovolideke.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- rivisoni.weebly.com
- wepugimi.weebly.com
- jawasolasazilem.weebly.com
- sesuwulot.weebly.com
- rakamukomegu.weebly.com
- gimejexoxixaza.weebly.com
- jumuwubugunitus.weebly.com
- povutepumik.weebly.com
- jukafubu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report