SUSPICIOUS — 12502777163.pdf
SUSPICIOUS — 12502777163.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5eac32dfe1a94a0b5f9932bf388af1387d94983a379c8b44440145ea54176204 - SHA-1:
01e33db882962a4054dcb51a990e94f337f8bd8b - MD5:
459848684bfe182c93410475f01b7fb3 - ssdeep:
1536:BGFnpjhgZPshc8tAhCOYJjpdhb/0g/qPU:kFnplHhFAIOgtdhDNaU - TLSH:
T17C34A0F3009BDD48B88AAB9399B5245CA00A9B8C6531936054DC77BEC5BC3BD7F20D61 - Submitted as: 12502777163.pdf
- File type: pdf · Size: 52810 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/b0b1e872-0523-4b6d-a4cf-cbd994593233/peteniginaxiwesikasi.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=carre+magique+special+tierce, https://site-1039514.mozfiles.com/files/1039514/28992693387.pdf, https://site-1037149.mozfiles.com/files/1037149/logafimopobiwazusid.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=carre+magique+special+tierce
- https://site-1039514.mozfiles.com/files/1039514/28992693387.pdf
- https://site-1037149.mozfiles.com/files/1037149/logafimopobiwazusid.pdf
- https://site-1038439.mozfiles.com/files/1038439/61361784322.pdf
- https://site-1043117.mozfiles.com/files/1043117/zudajovejilur.pdf
- https://uploads.strikinglycdn.com/files/b0b1e872-0523-4b6d-a4cf-cbd994593233/peteniginaxiwesikasi.pdf
- https://uploads.strikinglycdn.com/files/a42f9db3-539d-418f-9898-a538307ea008/61357494847.pdf
- https://uploads.strikinglycdn.com/files/38671412-aa5f-47f5-a053-fccfe0feda6e/48427424249.pdf
- https://uploads.strikinglycdn.com/files/cac62cf0-8ebb-420e-8c1c-b297b20804d4/burulujoduvowukomorudape.pdf
- https://uploads.strikinglycdn.com/files/7a77d290-755a-4ce5-92e4-8281ec5ebb96/risefufire.pdf
- https://uploads.strikinglycdn.com/files/5696e38d-5ea5-4d69-9af0-d5db35bc8b26/kikakezizulu.pdf
- https://uploads.strikinglycdn.com/files/372ad656-da2c-432f-b758-e5192fd7be25/nojowexaberudulisuwunegu.pdf
- https://uploads.strikinglycdn.com/files/5c522786-d02c-4921-9db7-e0f96fde9286/mofetegifitapufazupabez.pdf
- https://uploads.strikinglycdn.com/files/0c045d64-3410-42ba-bb4c-7e16a67467e7/24692936284.pdf
- https://uploads.strikinglycdn.com/files/d103bd32-f6df-4093-9d39-118172f09465/sebazenuzizumepegetep.pdf
- https://uploads.strikinglycdn.com/files/a895fac8-5717-4dee-b541-c4e2f10bb5b5/23974775317.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1039514.mozfiles.com
- site-1037149.mozfiles.com
- site-1038439.mozfiles.com
- site-1043117.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report