SUSPICIOUS — 38702562530.pdf
SUSPICIOUS — 38702562530.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
579b16897fb3faf4ab27786f47e8299e97c99ca7a09a2a457d37851f7978931b - SHA-1:
f535015d8d05cbac26bc182d8c6fe59edb8900f4 - MD5:
cdaf127eca3aed857be783cac0706867 - ssdeep:
768:rIgGzpDW+xJNam7UTyEoCK8jwx9c3VnT/BMS:rFGFaqJyTy1l8mc3VDBMS - TLSH:
T1BD319DF35063ED4C7A826F236FEA1859518AD34961329BB4948C3B7CC4BC2BD7E41960 - Submitted as: 38702562530.pdf
- File type: pdf · Size: 40522 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/c9a513f3-d84a-44df-a614-901a8b64d056/30472722838.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=case+studies+in+nursing+fundamentals+pdf, https://uploads.strikinglycdn.com/files/c9a513f3-d84a-44df-a614-901a8b64d056/30472722838.pdf, https://uploads.strikinglycdn.com/files/ba769586-a821-4238-bd85-3b850f173117/bakor.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=case+studies+in+nursing+fundamentals+pdf
- https://uploads.strikinglycdn.com/files/c9a513f3-d84a-44df-a614-901a8b64d056/30472722838.pdf
- https://uploads.strikinglycdn.com/files/ba769586-a821-4238-bd85-3b850f173117/bakor.pdf
- https://uploads.strikinglycdn.com/files/e5b0ccef-b78b-47bb-a080-274ab7209c6a/75147786566.pdf
- https://uploads.strikinglycdn.com/files/2469d0ae-80bc-4387-87c4-c447643750c2/89572137413.pdf
- https://site-1036744.mozfiles.com/files/1036744/zevemifofajolupew.pdf
- https://site-1039869.mozfiles.com/files/1039869/nibezajapine.pdf
- https://site-1040764.mozfiles.com/files/1040764/sogigujak.pdf
- https://site-1040988.mozfiles.com/files/1040988/lewuziteparo.pdf
- https://site-1037905.mozfiles.com/files/1037905/nazogu.pdf
- http://tulanak.dafniantonarou.com/uploads/1/3/1/4/131407629/ce07d45eef1.pdf
- http://files.maryprussellmacalt.com/uploads/1/3/2/6/132695493/4588846.pdf
- http://files.nebraskatraileroutlet.com/uploads/1/3/1/4/131483719/5930116.pdf
- http://files.blackmtnbengals.com/uploads/1/3/2/6/132681836/9404954.pdf
- http://lijegaza.laurenceremacle.com/uploads/1/3/1/4/131437940/4616442.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1036744.mozfiles.com
- site-1039869.mozfiles.com
- site-1040764.mozfiles.com
- site-1040988.mozfiles.com
- site-1037905.mozfiles.com
- tulanak.dafniantonarou.com
- files.maryprussellmacalt.com
- files.nebraskatraileroutlet.com
- files.blackmtnbengals.com
- lijegaza.laurenceremacle.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report