SUSPICIOUS — 53691151503.pdf
SUSPICIOUS — 53691151503.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2db65525982d371e129d100074e36127c4206741496fc03a45746b9df19d963d - SHA-1:
229e3439e68d5ca16d5176d04b180e2a2a2c0d40 - MD5:
6cb474ea82804953a402366704a60e24 - ssdeep:
768:t0gGzpDHQRVzN1Oq+mNwp76AFLQRjEjj62IbLrg2pmN+/D0qq3vjD+A1d:vGF7wzN1OdewN6MLw8g/k3vGA1d - TLSH:
T135328DF311E7DC8C3A86DB03AEAA296D9196CB48212296B015CD776CC4BC3BD7F10951 - Submitted as: 53691151503.pdf
- File type: pdf · Size: 43906 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://sinabo.199boxingwrestling.com/uploads/1/3/1/3/131384401/52185.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=b1+english+speaking+topics+pdf, https://uploads.strikinglycdn.com/files/7baf0fac-278f-4c90-87cb-2a75c6ad920c/65998315197.pdf, https://uploads.strikinglycdn.com/files/3a5d27b4-9e36-49e5-9a73-933eb54c0145/kirovipepig.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=b1+english+speaking+topics+pdf
- https://uploads.strikinglycdn.com/files/7baf0fac-278f-4c90-87cb-2a75c6ad920c/65998315197.pdf
- https://uploads.strikinglycdn.com/files/3a5d27b4-9e36-49e5-9a73-933eb54c0145/kirovipepig.pdf
- https://uploads.strikinglycdn.com/files/69349881-a2c6-4c66-bb08-639cbdf7b1bf/finodanaxolaxu.pdf
- http://jewefudo.inspirationactivated.net/uploads/1/3/1/6/131636627/13e7e72a231fa7f.pdf
- http://vabebe.ashfordportfolioairportexecutivetravel.co.uk/uploads/1/3/0/7/130774977/d6e12a9817.pdf
- http://files.hawkknifedesigns.com/uploads/1/3/1/4/131437181/ruvuvilunaw-bukob-gimadesikun.pdf
- http://sinabo.199boxingwrestling.com/uploads/1/3/1/3/131384401/52185.pdf
- http://getosa.wekeepyoumotivated.com/uploads/1/3/0/7/130739287/6037708.pdf
- https://uploads.strikinglycdn.com/files/971e6dcd-45a6-439a-9339-1036724a51aa/jajinut.pdf
- https://uploads.strikinglycdn.com/files/dcc52a80-3b19-4e82-8b22-59cbdeb78507/44351916478.pdf
- https://uploads.strikinglycdn.com/files/bb8ed003-d108-4130-9092-c845796075ae/fatukojefataxemavaxode.pdf
- https://cdn.shopify.com/s/files/1/0433/9132/0214/files/44699558974.pdf
- https://cdn.shopify.com/s/files/1/0470/9066/3582/files/mewani.pdf
- https://cdn.shopify.com/s/files/1/0431/6246/8516/files/jiwaxo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- jewefudo.inspirationactivated.net
- vabebe.ashfordportfolioairportexecutivetravel.co.uk
- files.hawkknifedesigns.com
- sinabo.199boxingwrestling.com
- getosa.wekeepyoumotivated.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- m:\,;P
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report