SUSPICIOUS — 72659412876.pdf
SUSPICIOUS — 72659412876.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (51/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
285fe90b7b2787947adaac1368d85fcfbaad27347faded77e3ec2924c997ab89 - SHA-1:
46b7f95f911f42dfac204fe7ffb8973b323d3032 - MD5:
441dc233e90f367fd2c1860f028a2649 - ssdeep:
768:sgGzpDieUqmmUzjN3c/ob7/QRly9wM+WOXIaOfw6e6YlnBL7VfRHTxUYrb:pGFuenuylZ5XIz26SVfFTxUYrb - TLSH:
T144316BF3109BED8C3AC7AB4369EB255D618ACB48A13297604898676CC5BC7BD3F00950 - Submitted as: 72659412876.pdf
- File type: pdf · Size: 42521 bytes
- Verdict: suspicious (51/100)
Detections (2 of 53 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 51/100 is the fusion of 3 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/5afa4cb3-ae3c-411e-83ed-722b6b62c4cf/turuxexuwerav.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=soleus+air+lx-140+nt+manual, https://uploads.strikinglycdn.com/files/5afa4cb3-ae3c-411e-83ed-722b6b62c4cf/turuxexuwerav.pdf, https://uploads.strikinglycdn.com/files/8e943985-4c9a-4363-9989-2b2b662c2abc/80496100143.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=soleus+air+lx-140+nt+manual
- https://uploads.strikinglycdn.com/files/5afa4cb3-ae3c-411e-83ed-722b6b62c4cf/turuxexuwerav.pdf
- https://uploads.strikinglycdn.com/files/8e943985-4c9a-4363-9989-2b2b662c2abc/80496100143.pdf
- https://uploads.strikinglycdn.com/files/eeadad09-7d07-4f6e-9059-7bd2df7bb144/84509356493.pdf
- https://uploads.strikinglycdn.com/files/32337c4d-da70-440f-9c76-eea2f0c0d357/sawufixegukonumefuf.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/8279037.pdf
- https://kasukironumasex.weebly.com/uploads/1/3/1/4/131454791/boguxudozoz_kibasosowaxur_xanudota_jawuvopiluvep.pdf
- https://tekegalesi.weebly.com/uploads/1/3/0/7/130740489/podox_nilore_karor_sakumanor.pdf
- https://site-1037145.mozfiles.com/files/1037145/97862238606.pdf
- https://site-1038413.mozfiles.com/files/1038413/kewokurixix.pdf
- https://site-1044417.mozfiles.com/files/1044417/dukez.pdf
- https://site-1038472.mozfiles.com/files/1038472/memejovuzesa.pdf
- https://site-1043878.mozfiles.com/files/1043878/novawiborakesujofu.pdf
- https://cdn.shopify.com/s/files/1/0432/3062/5950/files/86683324507.pdf
- https://cdn.shopify.com/s/files/1/0498/2453/0594/files/maytag_bravos_x_washer.pdf
- https://cdn.shopify.com/s/files/1/0484/5853/0966/files/85944378901.pdf
- https://cdn.shopify.com/s/files/1/0266/7921/4265/files/sedalia_elementary_school_ky.pdf
- https://cdn.shopify.com/s/files/1/0431/0233/9232/files/letter_formation_sheets.pdf
- https://cdn.shopify.com/s/files/1/0428/8934/7228/files/simple_machines_worksheet_physical_science.pdf
- https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/suwowu.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/palaj_xofepevez.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/9b53ec72f.pdf
- https://rozolabo.weebly.com/uploads/1/3/0/8/130814594/7777132.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/kedoxezezaj-temolej-zunemalavorun-mutelokowomimi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- fijojonibiw.weebly.com
- kasukironumasex.weebly.com
- tekegalesi.weebly.com
- site-1037145.mozfiles.com
- site-1038413.mozfiles.com
- site-1044417.mozfiles.com
- site-1038472.mozfiles.com
- site-1043878.mozfiles.com
- cdn.shopify.com
- sesuwulot.weebly.com
- guwomenod.weebly.com
- mogilifus.weebly.com
- rozolabo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report