SUSPICIOUS — 6296458322.pdf
SUSPICIOUS — 6296458322.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4c2e06145e4e9373f492905a0945ed127b5fb6e1f577ddc7d4fe3acb63a99c52 - SHA-1:
3b89c4ae6e9ed3eac9cb73f7253dac3b781b9b5e - MD5:
c148e7bb0d3e795fb91e90a22aa8ce3d - ssdeep:
768:IVgGzpDgpLEPcEqjzRta5x3kdzogu0Q8wITOYga82/amTegHgg8CtR8G7P47L2V:DGFMpooRl0fQOgR/HegAjo6Gj47L2V - TLSH:
T12A33AEB7509BDD8DA68B6B07ADB61158604EC28C216397B014DC7B2CC57CAFE7E40A10 - Submitted as: 6296458322.pdf
- File type: pdf · Size: 51643 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/ee67f427-df96-4723-9f49-427db525345b/bekedagusejolugewopafesok.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=read+beautiful+darkness+online+free, https://cdn.shopify.com/s/files/1/0484/0551/2349/files/riot_shotgun_vs_hunting_shotgun.pdf, https://cdn.shopify.com/s/files/1/0431/9870/9917/files/13979614078.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=read+beautiful+darkness+online+free
- https://cdn.shopify.com/s/files/1/0484/0551/2349/files/riot_shotgun_vs_hunting_shotgun.pdf
- https://cdn.shopify.com/s/files/1/0431/9870/9917/files/13979614078.pdf
- https://cdn.shopify.com/s/files/1/0432/9740/7126/files/sibumurirokumanuzemik.pdf
- https://cdn.shopify.com/s/files/1/0482/7906/0635/files/minecraft_apk_12.1_indir.pdf
- https://site-1041378.mozfiles.com/files/1041378/letelolajaje.pdf
- https://site-1036820.mozfiles.com/files/1036820/49095235696.pdf
- https://site-1043600.mozfiles.com/files/1043600/tevitoranuvupinosusilef.pdf
- https://uploads.strikinglycdn.com/files/ee67f427-df96-4723-9f49-427db525345b/bekedagusejolugewopafesok.pdf
- https://uploads.strikinglycdn.com/files/6acfd62d-4fe0-409f-9b50-3e78c6d34bfc/94260755211.pdf
- https://uploads.strikinglycdn.com/files/cf46f8b7-aa40-4dae-8aa9-33521f3288ed/nakutupobalirowobu.pdf
- https://uploads.strikinglycdn.com/files/2a4c8ff2-6f02-4252-bef6-e842ec76f9a2/xozezilesawuler.pdf
- https://uploads.strikinglycdn.com/files/2191c67a-f623-4b52-b30d-2ef44c267e99/58120411277.pdf
- https://site-1042658.mozfiles.com/files/1042658/53147675030.pdf
- https://site-1038700.mozfiles.com/files/1038700/zobugub.pdf
- https://site-1038856.mozfiles.com/files/1038856/vudojevojiwevodupad.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- site-1041378.mozfiles.com
- site-1036820.mozfiles.com
- site-1043600.mozfiles.com
- uploads.strikinglycdn.com
- site-1042658.mozfiles.com
- site-1038700.mozfiles.com
- site-1038856.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report