SUSPICIOUS — 94331924621.pdf
SUSPICIOUS — 94331924621.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
355d8970dd2ef8c4b75fe5c0ba7c652031412337544f604504fff57c2a2997aa - SHA-1:
413e5e7fca683d968444cca700e1bcf0f949cdc3 - MD5:
1c5f0ea058e5a1e5f01401b8b9eb9700 - ssdeep:
768:YgGzpDSFDfISgerEla/iJ5UU40mbgP32VI7ffqBeQ0u:1GFccSgerEla6J54bgPmGnQ0u - TLSH:
T18A319EF38467EC8C7AC2AB03AEBA1058214AD68C6027976058DC377DD47C6FD6E10E61 - Submitted as: 94331924621.pdf
- File type: pdf · Size: 40208 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/c34b723a-da0e-4e01-b37f-a7c25a6102c9/34348765086.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=wbut+cet+sample+question+paper, https://site-1039190.mozfiles.com/files/1039190/letidi.pdf, https://site-1036814.mozfiles.com/files/1036814/naruke.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=wbut+cet+sample+question+paper
- https://site-1039190.mozfiles.com/files/1039190/letidi.pdf
- https://site-1036814.mozfiles.com/files/1036814/naruke.pdf
- https://site-1039779.mozfiles.com/files/1039779/93837160400.pdf
- https://site-1038360.mozfiles.com/files/1038360/90231691007.pdf
- https://site-1038343.mozfiles.com/files/1038343/53018055282.pdf
- https://uploads.strikinglycdn.com/files/c34b723a-da0e-4e01-b37f-a7c25a6102c9/34348765086.pdf
- https://uploads.strikinglycdn.com/files/94174f34-005e-422b-8063-c859c64056f9/madubexusubeder.pdf
- https://uploads.strikinglycdn.com/files/be284216-f17e-4221-b5a7-405b2862dd96/23947951456.pdf
- http://files.drlendevilliers.com/uploads/1/3/0/8/130814761/268545.pdf
- http://files.sparc-evangelism.com/uploads/1/3/0/7/130776499/1eeeff07adb37.pdf
- https://uploads.strikinglycdn.com/files/bbca232a-0bb6-47b9-9eba-a889a8b7e201/61689317706.pdf
- https://uploads.strikinglycdn.com/files/568b2d88-01a0-4cbd-a584-adde350fd7b0/tivuzimex.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1039190.mozfiles.com
- site-1036814.mozfiles.com
- site-1039779.mozfiles.com
- site-1038360.mozfiles.com
- site-1038343.mozfiles.com
- uploads.strikinglycdn.com
- files.drlendevilliers.com
- files.sparc-evangelism.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report