SUSPICIOUS — 88896784702.pdf
SUSPICIOUS — 88896784702.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4961958f5d28796e82f5cbbd0276a97e99e3331b9662aae296e4e87ef9de57ad - SHA-1:
bd21c212223965c75fbe3dd9b5d8d7751f287d3e - MD5:
06cf9f86f12771f2e417c8f3ef4f9332 - ssdeep:
1536:LGFN7GPcV/iP6o0UAcQdR4mRdXrEJELZhbh:qFN7q6/Y6q/IR4GdXrEJELd - TLSH:
T11A33ADF310A7ED4CBA8B6B076DA31059904AD78D6136EBA014887B2CC4BC6FD7E10665 - Submitted as: 88896784702.pdf
- File type: pdf · Size: 50421 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/6a136c12-3fce-420c-b060-0ec02d72b876/63078446904.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=minecraft+1.5+2+hunger+games+server, https://cdn.shopify.com/s/files/1/0428/9980/0217/files/m_butterfly_download.pdf, https://cdn.shopify.com/s/files/1/0483/2257/6548/files/57357390322.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=minecraft+1.5+2+hunger+games+server
- https://cdn.shopify.com/s/files/1/0428/9980/0217/files/m_butterfly_download.pdf
- https://cdn.shopify.com/s/files/1/0483/2257/6548/files/57357390322.pdf
- https://cdn.shopify.com/s/files/1/0498/7607/4654/files/cpt_exam_study_guide.pdf
- https://cdn.shopify.com/s/files/1/0432/5851/1510/files/92314347569.pdf
- https://cdn.shopify.com/s/files/1/0481/6224/2727/files/la_historia_de_la_geometria.pdf
- https://cdn.shopify.com/s/files/1/0435/3182/9412/files/rizov.pdf
- https://cdn.shopify.com/s/files/1/0428/3524/7271/files/linksys_connect_software_wrt54g.pdf
- https://cdn.shopify.com/s/files/1/0433/0281/3849/files/vofuxu.pdf
- https://cdn.shopify.com/s/files/1/0482/2941/7112/files/6711314407.pdf
- https://uploads.strikinglycdn.com/files/6a136c12-3fce-420c-b060-0ec02d72b876/63078446904.pdf
- https://uploads.strikinglycdn.com/files/27c1c317-bf9d-4b79-8f7a-8a9bec623bb7/44296216927.pdf
- https://uploads.strikinglycdn.com/files/1010b530-8ae7-40d6-bb29-6ecd593b440b/fesoz.pdf
- https://uploads.strikinglycdn.com/files/5091d880-391e-4d44-ba3a-82ff920c300e/risakatu.pdf
- https://uploads.strikinglycdn.com/files/d3cb5741-9cda-43e5-8e40-05d8c1b6f79c/96082834962.pdf
- https://cdn.shopify.com/s/files/1/0482/8990/6852/files/calvin_klein_sheets_tj_maxx.pdf
- https://cdn.shopify.com/s/files/1/0480/6901/7763/files/tintinalli_emergency_medicine_manual.pdf
- https://cdn.shopify.com/s/files/1/0479/7408/8860/files/nujuvasikafoxivuvojuguvi.pdf
- https://cdn.shopify.com/s/files/1/0479/5993/3084/files/latodiboximamavati.pdf
- https://cdn.shopify.com/s/files/1/0432/2426/8968/files/87582667274.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report