SUSPICIOUS — 99347153f7d46.pdf
SUSPICIOUS — 99347153f7d46.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3c6ffce8efc5c494e5c45fe3bfa770e768e4cb764ab3be03d2734a22cb599396 - SHA-1:
9977579a0fe90993f4da7542b5c84a92df639c8f - MD5:
0d0402083f2e5c0ad33bfcff01e703ce - ssdeep:
768:SgGzpDrpK8fBZUWsd5NEWpnBTdHha3FE681Dh2Jcc1Ma4bKOlyBF:PGFPpDWacnBJHha3e681DhAV1bOaF - TLSH:
T127329EF74497DD4CBB8A9B076DAB00649089C349A267D36099CC772DD4BC9FDBE108A0 - Submitted as: 99347153f7d46.pdf
- File type: pdf · Size: 47454 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/c8f6af64-c3a7-487d-94a5-670a95807aaf/56799802725.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=skyrim%20enchanters%20potion%20recipe, https://site-1044062.mozfiles.com/files/1044062/ph_and_enzyme_activity.pdf, https://site-1036858.mozfiles.com/files/1036858/nubanugawalobutuv.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=skyrim%20enchanters%20potion%20recipe
- https://site-1044062.mozfiles.com/files/1044062/ph_and_enzyme_activity.pdf
- https://site-1036858.mozfiles.com/files/1036858/nubanugawalobutuv.pdf
- https://site-1036699.mozfiles.com/files/1036699/14582311328.pdf
- https://site-1039498.mozfiles.com/files/1039498/26208891461.pdf
- https://uploads.strikinglycdn.com/files/c8f6af64-c3a7-487d-94a5-670a95807aaf/56799802725.pdf
- https://cdn.shopify.com/s/files/1/0434/8765/8150/files/white_wine_in_the_sun_chords.pdf
- https://cdn.shopify.com/s/files/1/0484/9873/7302/files/kewuli.pdf
- https://cdn.shopify.com/s/files/1/0496/0105/2836/files/mutant_creatures_mod_1.12.2.pdf
- https://cdn.shopify.com/s/files/1/0483/9951/5816/files/misisutetinavekopi.pdf
- https://uploads.strikinglycdn.com/files/cbb6eba6-0a9a-43cc-8c0d-e7e8baf72eb6/zewiromolopufusajaj.pdf
- https://uploads.strikinglycdn.com/files/79465003-4cfa-4de7-bdde-bd87b9c072d4/rijanoritorasumenu.pdf
- https://uploads.strikinglycdn.com/files/31e35bf2-b56f-4ac4-b036-46e53a286a62/71714424832.pdf
- https://uploads.strikinglycdn.com/files/11435c4a-0df4-45d7-ac5f-bb67db3ec82c/vitexop.pdf
- https://uploads.strikinglycdn.com/files/2848a7c4-4716-486e-b581-bb76d178f098/fefowid.pdf
- https://site-1037907.mozfiles.com/files/1037907/46773974775.pdf
- https://site-1042419.mozfiles.com/files/1042419/40101453990.pdf
- https://site-1037071.mozfiles.com/files/1037071/daragime.pdf
- https://site-1040221.mozfiles.com/files/1040221/liwititubuwofagadugin.pdf
- https://site-1042679.mozfiles.com/files/1042679/kegetininarumagopifa.pdf
- https://uploads.strikinglycdn.com/files/02d8eabb-c711-4d22-ae04-fbae9d61a87e/58985494205.pdf
- https://uploads.strikinglycdn.com/files/0e579b98-fb91-4f92-94cd-091208d9fa8b/60645715900.pdf
- https://uploads.strikinglycdn.com/files/b6a2b245-705c-4c4b-8183-2323f8755bf5/kijisotukigesirubuvex.pdf
- https://uploads.strikinglycdn.com/files/01a39cac-4039-4e2b-973b-f6b88aa6306a/dozitewunevujerod.pdf
- https://uploads.strikinglycdn.com/files/2dedc58e-435d-4309-b4d5-d1b0e969fa91/5005579558.pdf
Embedded domains
- gettraff.ru
- site-1044062.mozfiles.com
- site-1036858.mozfiles.com
- site-1036699.mozfiles.com
- site-1039498.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1037907.mozfiles.com
- site-1042419.mozfiles.com
- site-1037071.mozfiles.com
- site-1040221.mozfiles.com
- site-1042679.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report