SUSPICIOUS — 21035294765.pdf
SUSPICIOUS — 21035294765.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3f6765fd0abce03e2fed06cd4b6c2cb97971aed23062dfe2c37b40a1293b9aef - SHA-1:
4c365ec70f11f29f3dddd9d7a697ba0a6d4be1f5 - MD5:
aa30c1868acb6c9ec758fb15c69ad166 - ssdeep:
768:kgGzpDsear6tX99seLx81DMZK7RVVglsHRadY5mUgtp8cXx:RGFwq2Qx8ZIK7/VlWEmUMp8ux - TLSH:
T1CA31AEF358A7DC8C6A87AB439DEB11599089D388603797A028D87B3DC17C6FDBE10560 - Submitted as: 21035294765.pdf
- File type: pdf · Size: 42124 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://files.stmarysclinic.net/uploads/1/3/1/3/131379830/sixesunilexupepazure.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=adjprog+l1300+free, http://files.alvarezorganics.com/uploads/1/3/1/6/131637240/d1e2aaa.pdf, http://files.stmarysclinic.net/uploads/1/3/1/3/131379830/sixesunilexupepazure.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=adjprog+l1300+free
- http://files.alvarezorganics.com/uploads/1/3/1/6/131637240/d1e2aaa.pdf
- http://files.stmarysclinic.net/uploads/1/3/1/3/131379830/sixesunilexupepazure.pdf
- http://files.belfastdrivered.com/uploads/1/3/1/3/131382274/wexamotovonezit-pabelirenakexo-robuniwobunoru.pdf
- http://tumowowa.fussfreefunerals.com/uploads/1/3/0/9/130969352/1451085.pdf
- http://files.ckbeagles.com/uploads/1/3/1/4/131452913/gokapodokulujome.pdf
- https://uploads.strikinglycdn.com/files/426e0e46-aac7-48c4-8c85-0fcb1b0e67fd/wanibidebasi.pdf
- https://uploads.strikinglycdn.com/files/bade9fca-9268-4ca1-8e41-267d2fc7e593/renesolobogore.pdf
- https://uploads.strikinglycdn.com/files/a99dbb17-6add-4c30-bbb4-e2a090f82b2b/59664037533.pdf
- https://uploads.strikinglycdn.com/files/2fe06f7e-d388-46ec-af16-569b64dbde2f/1062884065.pdf
- https://uploads.strikinglycdn.com/files/72cde9b9-513d-4620-9b99-5b6c128c884d/texepukipof.pdf
- https://site-1036722.mozfiles.com/files/1036722/7570109597.pdf
- https://site-1036750.mozfiles.com/files/1036750/88202625683.pdf
- https://site-1037188.mozfiles.com/files/1037188/suxow.pdf
- https://site-1036973.mozfiles.com/files/1036973/tobavawabo.pdf
- https://site-1037079.mozfiles.com/files/1037079/23337248163.pdf
- https://site-1039133.mozfiles.com/files/1039133/noraduvovemotowuwe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- files.alvarezorganics.com
- files.stmarysclinic.net
- files.belfastdrivered.com
- tumowowa.fussfreefunerals.com
- files.ckbeagles.com
- uploads.strikinglycdn.com
- site-1036722.mozfiles.com
- site-1036750.mozfiles.com
- site-1037188.mozfiles.com
- site-1036973.mozfiles.com
- site-1037079.mozfiles.com
- site-1039133.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report