SUSPICIOUS — 36510827618.pdf
SUSPICIOUS — 36510827618.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
514036a79ac75a3dbab80c9807f8ce532c593cc8dec1b437e68a0c31b5d2c9b7 - SHA-1:
84f7464d38318ce922e3b8a9ed85593d3e192d77 - MD5:
25a54d039175b699bfbabecc0decad38 - ssdeep:
768:HgGzpDmLJQsLS7DS/w0UVrzFK27bgsp419Yxr18g5BjdmG1uQOZG:AGFyNAkxURhJvR+YNXTdLbOZG - TLSH:
T1FB319EF341EBEC8C7A876B077EF610956189C28D7126A7B04898773ED4BC5BD6E10920 - Submitted as: 36510827618.pdf
- File type: pdf · Size: 40043 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/f35b3b5e-6142-46d6-a5a7-1fa10fc54c93/72472905283.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=transitive+and+intransitive+verb+wor, https://site-1037124.mozfiles.com/files/1037124/24419611149.pdf, https://site-1036693.mozfiles.com/files/1036693/fasusawerasoweru.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=transitive+and+intransitive+verb+wor
- https://site-1037124.mozfiles.com/files/1037124/24419611149.pdf
- https://site-1036693.mozfiles.com/files/1036693/fasusawerasoweru.pdf
- https://site-1039319.mozfiles.com/files/1039319/nasaranemameretivusugeron.pdf
- https://site-1037103.mozfiles.com/files/1037103/robewivusuvimawekuzolo.pdf
- https://uploads.strikinglycdn.com/files/b30cac94-8d8a-4bd7-89f6-3d783fa97175/fejuxakasixinomova.pdf
- https://uploads.strikinglycdn.com/files/4925a357-fd00-4e9d-a7ea-701e2274bf08/tulabedudafajo.pdf
- https://uploads.strikinglycdn.com/files/f35b3b5e-6142-46d6-a5a7-1fa10fc54c93/72472905283.pdf
- https://uploads.strikinglycdn.com/files/59dc58fd-697c-4062-a931-d4279e0f6346/70823063261.pdf
- https://uploads.strikinglycdn.com/files/95d5a3b7-1382-4abd-a73c-fbeace6796c1/54788106180.pdf
- https://site-1039604.mozfiles.com/files/1039604/6473045890.pdf
- https://site-1039929.mozfiles.com/files/1039929/jijasusezosaxa.pdf
- https://site-1040242.mozfiles.com/files/1040242/90728300916.pdf
- https://site-1036692.mozfiles.com/files/1036692/pijakavekasi.pdf
- https://site-1036975.mozfiles.com/files/1036975/femiguwamiwenoz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1037124.mozfiles.com
- site-1036693.mozfiles.com
- site-1039319.mozfiles.com
- site-1037103.mozfiles.com
- uploads.strikinglycdn.com
- site-1039604.mozfiles.com
- site-1039929.mozfiles.com
- site-1040242.mozfiles.com
- site-1036692.mozfiles.com
- site-1036975.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report