SUSPICIOUS — 7968977844.pdf
SUSPICIOUS — 7968977844.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2a7ecb4c18c422c86fa27ce681c2b603966b7f75e86f321ebbc0965b7bc62cbb - SHA-1:
c40e2c159c6bf5d05ca96f17d434e30c87bd8f4b - MD5:
905771a8ac98b59c7d5dba4460ad0239 - ssdeep:
768:CgGzpDc8W9N96hAgcDfdFabZ1Ij37QppRbwPi1VsR+q:fGFALFTabZC37wp1QpR+q - TLSH:
T137308DF350A3DC4C3ACAAB17ADE7119D608AC78CB136A6605988772CC47C6FD7E40661 - Submitted as: 7968977844.pdf
- File type: pdf · Size: 39227 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/0af163b6-2386-49eb-88db-65dd7bf7512e/minujekanitike.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=peta+rtrw+kabupaten+bandung+barat+pdf, https://uploads.strikinglycdn.com/files/0af163b6-2386-49eb-88db-65dd7bf7512e/minujekanitike.pdf, https://uploads.strikinglycdn.com/files/9aed48a5-1a6a-4e9a-bc61-9e87a3ce4c9b/67819153451.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=peta+rtrw+kabupaten+bandung+barat+pdf
- https://uploads.strikinglycdn.com/files/0af163b6-2386-49eb-88db-65dd7bf7512e/minujekanitike.pdf
- https://uploads.strikinglycdn.com/files/9aed48a5-1a6a-4e9a-bc61-9e87a3ce4c9b/67819153451.pdf
- https://uploads.strikinglycdn.com/files/53af94df-92b1-4906-b6e9-87df86d5f4b0/xuvivuduzexivodove.pdf
- https://uploads.strikinglycdn.com/files/cdb85020-b49d-41c5-9719-12b4fc5ae48a/xovuxobopaxuk.pdf
- https://uploads.strikinglycdn.com/files/0e4687f3-6ad5-4964-8bda-8f7511197284/tiwuroxubisipadifikotamep.pdf
- https://site-1037920.mozfiles.com/files/1037920/32219116582.pdf
- https://site-1037262.mozfiles.com/files/1037262/50401552028.pdf
- https://site-1036951.mozfiles.com/files/1036951/62715486463.pdf
- https://site-1036744.mozfiles.com/files/1036744/40294936788.pdf
- https://cdn.shopify.com/s/files/1/0433/4508/4574/files/felox.pdf
- https://cdn.shopify.com/s/files/1/0436/8026/8438/files/biblia_scofield_descargar.pdf
- https://cdn.shopify.com/s/files/1/0433/5878/1590/files/sapirebijelozunegudiwudiz.pdf
- https://cdn.shopify.com/s/files/1/0484/5479/5414/files/spring_bonnie_into_the_pit.pdf
- https://cdn.shopify.com/s/files/1/0440/1194/6134/files/boylan_root_beer_-_12_oz.pdf
- http://gixozo.javelinuk.org/uploads/1/3/1/4/131406861/jumimubikisujob_wabixu.pdf
- http://files.youthandloud.org/uploads/1/3/0/9/130969083/janamezitefuwisogen.pdf
- http://niteti.nulineeducon.com/uploads/1/3/1/6/131607240/visejutisa_selinetilerexo_zizofenoxagire_josibaxan.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1037920.mozfiles.com
- site-1037262.mozfiles.com
- site-1036951.mozfiles.com
- site-1036744.mozfiles.com
- cdn.shopify.com
- gixozo.javelinuk.org
- files.youthandloud.org
- niteti.nulineeducon.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report