SUSPICIOUS — 23659821270.pdf
SUSPICIOUS — 23659821270.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
48742e6d9dafd3ff4b8661f690678c898d66322ff4a4a47f7361112be7d9c907 - SHA-1:
6f4c23067eae57e17d827935c49140125cc052de - MD5:
0d68a2c79df398bd17ccc454a18bae00 - ssdeep:
1536:nGFqp4umwo/iWvEjEFuHeUY9Hq7YE4qIkWVYrr9b:GFqpcXFu+UaHw4TJYrd - TLSH:
T126358DF300B7EE8C7687EB836DEA151864998B883172A6A04488773CC57C37DBF51991 - Submitted as: 23659821270.pdf
- File type: pdf · Size: 57751 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://files.driscollmspta.com/uploads/1/3/1/6/131607827/wagufusafeka_xatikese_rejirurapede.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=romanticismo+literario+espa%25C3%25B1ol+pdf, http://files.peacefulexperience.com/uploads/1/3/0/9/130969176/6e06e5568.pdf, http://datarokap.ruinenjunkie.com/uploads/1/3/0/7/130775643/sinagun.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=romanticismo+literario+espa%25C3%25B1ol+pdf
- http://files.peacefulexperience.com/uploads/1/3/0/9/130969176/6e06e5568.pdf
- http://datarokap.ruinenjunkie.com/uploads/1/3/0/7/130775643/sinagun.pdf
- http://zurov.flowerdeb.com/uploads/1/3/1/8/131856166/didozepuj-bafabovorusiz.pdf
- http://lizox.nicholesallescunha.com/uploads/1/3/1/4/131406379/lilagawewiw_baposulezedojiw_zaxujikod.pdf
- http://voxaseser.soviet-shrek.com/uploads/1/3/1/4/131483400/nigeg.pdf
- https://site-1043837.mozfiles.com/files/1043837/dejilawasafoladeb.pdf
- http://files.driscollmspta.com/uploads/1/3/1/6/131607827/wagufusafeka_xatikese_rejirurapede.pdf
- http://files.esslondon.ca/uploads/1/3/1/3/131384145/7fadbf2d2eb0.pdf
- http://files.williambmusic.com/uploads/1/3/0/7/130739290/dewijalitob-vamezodagoke-bunetufug-najem.pdf
- http://files.manaskalar.com/uploads/1/3/1/4/131413678/4835295.pdf
- http://files.campdavidnj.com/uploads/1/3/1/4/131454219/30c80b8e16e83f.pdf
- https://uploads.strikinglycdn.com/files/fc867014-9239-48a7-b6bc-bd0b569672c8/76149795791.pdf
- https://uploads.strikinglycdn.com/files/0f0fbd84-bfeb-4493-a62e-91d16afcbcac/nonedulejavokuxexezo.pdf
- https://uploads.strikinglycdn.com/files/c07b4954-dd8c-4311-9377-e888d8f15399/88526545451.pdf
- https://uploads.strikinglycdn.com/files/f62fab03-9d99-43bc-9c75-a5635115449f/50731740610.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- files.peacefulexperience.com
- datarokap.ruinenjunkie.com
- zurov.flowerdeb.com
- lizox.nicholesallescunha.com
- voxaseser.soviet-shrek.com
- site-1043837.mozfiles.com
- files.driscollmspta.com
- files.esslondon.ca
- files.williambmusic.com
- files.manaskalar.com
- files.campdavidnj.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report