SUSPICIOUS — 72701914545.pdf
SUSPICIOUS — 72701914545.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3bc5738a11ba72a47c929d03a04e16ebc41936859fc4dc526743bc5353f03be6 - SHA-1:
ee2e667b819bf1cc8ce8137ffe94b6335bf35e77 - MD5:
701bf41839f6061b1ef1df05e6e3fdd1 - ssdeep:
768:CgGzpDr938z60cMPzc6lvVETVKejj6v69rW6HJ/uinkcbEE+290LM/O+iRL:fGFv9Ubc0vjk19/ukkoEE19L/O+iRL - TLSH:
T132339DF350A7DD8D3A4B6B035EEA059D604AC68C722397A504887BACC47C6FC6E11A52 - Submitted as: 72701914545.pdf
- File type: pdf · Size: 48524 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/de488957-6e09-4a02-8b92-badd479eef8f/lebipopokevikomu.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=a+wrinkle+in+time+comprehension+questions+pdf, https://uploads.strikinglycdn.com/files/de488957-6e09-4a02-8b92-badd479eef8f/lebipopokevikomu.pdf, https://uploads.strikinglycdn.com/files/78184dd4-d272-4470-a2ab-c0ce3378b069/44769461606.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=a+wrinkle+in+time+comprehension+questions+pdf
- https://uploads.strikinglycdn.com/files/de488957-6e09-4a02-8b92-badd479eef8f/lebipopokevikomu.pdf
- https://uploads.strikinglycdn.com/files/78184dd4-d272-4470-a2ab-c0ce3378b069/44769461606.pdf
- https://uploads.strikinglycdn.com/files/5716139a-fe2e-42e3-abba-f52a859437e7/9938962569.pdf
- https://uploads.strikinglycdn.com/files/772ed879-755e-4d89-b846-ac5b580f596a/46210987536.pdf
- https://uploads.strikinglycdn.com/files/ef06e240-6687-4ee6-96b6-e8ac2c136972/72441481358.pdf
- https://uploads.strikinglycdn.com/files/236e3e30-edf1-473c-9aa3-3b1be6a24c74/57699418275.pdf
- https://cdn.shopify.com/s/files/1/0431/1223/5159/files/germantown_municipal_schools_twitter.pdf
- https://cdn.shopify.com/s/files/1/0436/0346/0259/files/skyrim_college_of_winterhold_quest_dwarven_puzzle.pdf
- https://cdn.shopify.com/s/files/1/0437/2119/5669/files/best_boomilever_designs.pdf
- https://cdn.shopify.com/s/files/1/0431/1891/9837/files/75343392091.pdf
- https://cdn.shopify.com/s/files/1/0484/6043/1514/files/bitcoin_mining_profitability_reddit.pdf
- http://xuzenup.runninsranch.com/uploads/1/3/1/4/131437626/wikerepoviravabik.pdf
- http://files.hornywheelers.com/uploads/1/3/1/3/131382470/biwer_gowuziroguxis_daxuveluw_jagawuvaxapazil.pdf
- http://wujagufa.adventurehorizons.com/uploads/1/3/1/3/131379956/tosisalex.pdf
- http://files.mauiskydiving.info/uploads/1/3/1/1/131163691/serijukujeniwupo.pdf
- http://files.starviewucc.org/uploads/1/3/0/7/130739871/buxojowoma.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- xuzenup.runninsranch.com
- files.hornywheelers.com
- wujagufa.adventurehorizons.com
- files.mauiskydiving.info
- files.starviewucc.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report