SUSPICIOUS — 40524234798.pdf
SUSPICIOUS — 40524234798.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6bd62960a4e973aa12ed56eb85745e0ae736282840db8c1ce90cb9b6145efa5b - SHA-1:
7f47cd914053307ca483406ed9fb9e928b36175b - MD5:
a1f876a1e7688a6a58a1b78164cb37cd - ssdeep:
768:0gGzpD48rEbcUpqanVjHtJLD8vRZwY4XXs3xfFFU7SvJL7zWDog3hnp5IQlHuUeg:BGFU8q1nxHtJkvZxfFPzW13hPIy4mCc - TLSH:
T1CC34AEB35057ED8C3B8B5F436EEB05D96059C78DA232D6A04498BBACD4BC2EC6F40611 - Submitted as: 40524234798.pdf
- File type: pdf · Size: 54673 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://zarikit.wicknscents.com/uploads/1/3/2/8/132815806/pafepimamuwoxi.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=blacklist+episode+guide+spoilers, https://site-1036884.mozfiles.com/files/1036884/72219488736.pdf, https://site-1036742.mozfiles.com/files/1036742/malamubitowigubomoz.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=blacklist+episode+guide+spoilers
- https://site-1036884.mozfiles.com/files/1036884/72219488736.pdf
- https://site-1036742.mozfiles.com/files/1036742/malamubitowigubomoz.pdf
- https://site-1039743.mozfiles.com/files/1039743/dokab.pdf
- https://cdn.shopify.com/s/files/1/0484/6537/9489/files/roosters_vernon_hills.pdf
- https://cdn.shopify.com/s/files/1/0429/0756/6239/files/40194225697.pdf
- https://cdn.shopify.com/s/files/1/0436/4907/3312/files/best_idle_games_2018_pc.pdf
- https://cdn.shopify.com/s/files/1/0429/2005/0855/files/85861015850.pdf
- https://cdn.shopify.com/s/files/1/0434/3853/8908/files/chapter_4_frappy_1997_problem_6_answers.pdf
- http://zarikit.wicknscents.com/uploads/1/3/2/8/132815806/pafepimamuwoxi.pdf
- http://files.nick-wright.com/uploads/1/3/0/9/130969999/06a41223d998446.pdf
- https://site-1040001.mozfiles.com/files/1040001/zazoxefab.pdf
- https://site-1036734.mozfiles.com/files/1036734/ganiwowa.pdf
- https://site-1036659.mozfiles.com/files/1036659/sanebaxezajavozete.pdf
- https://site-1036884.mozfiles.com/files/1036884/pebazegelisametozu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1036884.mozfiles.com
- site-1036742.mozfiles.com
- site-1039743.mozfiles.com
- cdn.shopify.com
- zarikit.wicknscents.com
- files.nick-wright.com
- site-1040001.mozfiles.com
- site-1036734.mozfiles.com
- site-1036659.mozfiles.com
- a.fi
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report