SUSPICIOUS — 64846142158.pdf
SUSPICIOUS — 64846142158.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5a9f35544d73873630773cad0e14deba0d73face76ddf7567ac430cc05047d5e - SHA-1:
67c24739b376c754d115b22fbdec6b6d048035a4 - MD5:
ccade92d624e28ba85fe0581e74f60d6 - ssdeep:
768:RgGzpDoqVJHuj9URQqmWr9v18qA1T1hmQ/yFE:iGFMAHujoQqmWr9CqKhmQaFE - TLSH:
T12A308EF300A7EDCC7E9BAB079DEB006D6246C68C603796A445DC3A6CC4B85FD6D10961 - Submitted as: 64846142158.pdf
- File type: pdf · Size: 36659 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/7aba2cac-2158-45ad-bd07-f8e95b4020a8/limawusumeduxaxad.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=bootstrap+4+bangla+tutorial+pdf, https://uploads.strikinglycdn.com/files/7aba2cac-2158-45ad-bd07-f8e95b4020a8/limawusumeduxaxad.pdf, https://uploads.strikinglycdn.com/files/c8d856cd-ba7a-4723-a26f-b4b1621981bf/19838995761.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=bootstrap+4+bangla+tutorial+pdf
- https://uploads.strikinglycdn.com/files/7aba2cac-2158-45ad-bd07-f8e95b4020a8/limawusumeduxaxad.pdf
- https://uploads.strikinglycdn.com/files/c8d856cd-ba7a-4723-a26f-b4b1621981bf/19838995761.pdf
- https://uploads.strikinglycdn.com/files/7f600cce-b2fa-465e-84e0-eb37adfc7a84/mazotewusura.pdf
- https://uploads.strikinglycdn.com/files/e233f5eb-3ecc-4db3-9cd6-d52485284a2d/lotipuwalojenav.pdf
- https://site-1036685.mozfiles.com/files/1036685/62439895320.pdf
- https://site-1036923.mozfiles.com/files/1036923/ditof.pdf
- https://site-1038412.mozfiles.com/files/1038412/dituraxipupiwixu.pdf
- http://kagoj.artscollective.co.nz/uploads/1/3/1/6/131606271/barogazuxisaxivoze.pdf
- http://files.justjumpkaty.com/uploads/1/3/0/7/130739298/21182.pdf
- http://kibosozu.cagleauction.net/uploads/1/3/1/4/131438418/dejajoxa.pdf
- http://nukenag.writespacejerusalem.com/uploads/1/3/0/7/130738526/serexot_bapot.pdf
- http://files.themojoradioshow.com/uploads/1/3/1/8/131856170/3871394.pdf
- http://jedewi.jsmountainpondfarm.com/uploads/1/3/1/0/131070934/3186564.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1036685.mozfiles.com
- site-1036923.mozfiles.com
- site-1038412.mozfiles.com
- files.justjumpkaty.com
- kibosozu.cagleauction.net
- nukenag.writespacejerusalem.com
- files.themojoradioshow.com
- jedewi.jsmountainpondfarm.com
- www.w3.org
- purl.org
- ns.adobe.com
- kagoj.artscollective.co.nz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report