SUSPICIOUS — 3177057.pdf
SUSPICIOUS — 3177057.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
549cff45882ef6ac85f809e5e84a1701bdebf69e56634ce8360eeddfd43e5efa - SHA-1:
4762787dca07b6f30aa9c88c7295d226f764b4f0 - MD5:
a275d4e79e2f2a66ba1a62a64a3c6ece - ssdeep:
768:SgGzpDPMMJbioHo1+3v7vvr08WFyzG0WRwbjnnYnYOYViK2dDXp:PGFbXloMDvj08B5WRwbjncYi9DXp - TLSH:
T115327DF35197ED9C3A8B9B079DBB1569518AC38C6036976048CC332DC4BCAEE6F10A51 - Submitted as: 3177057.pdf
- File type: pdf · Size: 46032 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:PDF/Phish!atmn
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/d277d71b-e317-4551-b1bb-d72a20df8f94/31325131272.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=philosophical%20foundations%20of%20education%20book%20pdf, https://uploads.strikinglycdn.com/files/d277d71b-e317-4551-b1bb-d72a20df8f94/31325131272.pdf, https://uploads.strikinglycdn.com/files/c0e090c9-ed4a-4ff5-9f0a-0ded13c1605d/gofurut.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=philosophical%20foundations%20of%20education%20book%20pdf
- https://uploads.strikinglycdn.com/files/d277d71b-e317-4551-b1bb-d72a20df8f94/31325131272.pdf
- https://uploads.strikinglycdn.com/files/c0e090c9-ed4a-4ff5-9f0a-0ded13c1605d/gofurut.pdf
- https://uploads.strikinglycdn.com/files/a372f69f-dbf2-43fd-8a58-20b5f5d7781a/36489634481.pdf
- https://uploads.strikinglycdn.com/files/30dc2790-c834-42b6-9bf2-989b56e20ce0/rukiveniza.pdf
- https://uploads.strikinglycdn.com/files/8ef83c1e-62bb-49db-bfbc-120c3492df1f/7095172274.pdf
- https://uploads.strikinglycdn.com/files/e705e4f9-76f5-468d-bbed-2eba269e080f/delta_gamma_sorority_anchor.pdf
- https://uploads.strikinglycdn.com/files/41ed9068-bc6d-40e4-ad5c-275e1feff0e8/45690431916.pdf
- https://uploads.strikinglycdn.com/files/84745e2f-cddd-4dab-820e-66c6ff61b4eb/18984189688.pdf
- https://uploads.strikinglycdn.com/files/fdcc476c-6962-4d5b-94ff-442ce35e6312/xotokib.pdf
- https://uploads.strikinglycdn.com/files/2bd66222-2b50-4345-b9c7-5fe31122f305/9272150798.pdf
- https://uploads.strikinglycdn.com/files/cd979486-5087-4d29-830b-6c92bda49b7c/14440486792.pdf
- https://uploads.strikinglycdn.com/files/96efb459-2e9a-475c-8134-0820ef3ac2e0/stock_investing_for_dummies_audiobook_free_download.pdf
- https://uploads.strikinglycdn.com/files/6aa65a3a-2038-40ea-ba2c-5c20a78933aa/losibutamigewuxexutedijo.pdf
- https://uploads.strikinglycdn.com/files/bc3db597-5209-4a4d-8c42-099a40ce620f/38709446753.pdf
- https://uploads.strikinglycdn.com/files/48144c1f-b7ed-4595-8791-5be3cf5e42ed/55711705619.pdf
- https://cdn-cms.f-static.net/uploads/4374963/normal_5f8cae9bd4aec.pdf
- https://cdn-cms.f-static.net/uploads/4366630/normal_5f90c56197eca.pdf
- https://cdn-cms.f-static.net/uploads/4367268/normal_5f8bc2154ea25.pdf
- https://s3.amazonaws.com/susopuzupure/automobile_engineering_free.pdf
- https://s3.amazonaws.com/zomuzigo/fexoludad.pdf
- https://s3.amazonaws.com/kavitokolezub/29842493593.pdf
- https://s3.amazonaws.com/wiwamoxamo/oxford_bookworms_stage_1_download.pdf
- https://s3.amazonaws.com/susopuzupure/vonezot.pdf
- https://uploads.strikinglycdn.com/files/839004f6-d57a-4c9a-9492-b076c73ce440/bijiwanidu.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report