SUSPICIOUS — 31265393116.pdf
SUSPICIOUS — 31265393116.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6dec09e09e2cfb5045d7516a60281756682d02936be15703d79ebb62c5543839 - SHA-1:
dec93ed17c5dd33a44aa66af6d02e53f675d6374 - MD5:
380fb986e3a043144add40d9eb208239 - ssdeep:
768:5gGzpD/pX2eVxu7dXMjWePVPgCHbTdSyiiJ1sU+vzp0G96sft1OYXBKxH7O:6GFzpEKLVSXvzpt6sVvEB7O - TLSH:
T192338DF310D7EE8C7A8BAF07AEE61499658EC348623797A0548C732CC4BC5AD7E11941 - Submitted as: 31265393116.pdf
- File type: pdf · Size: 49121 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://cdn-cms.f-static.net/uploads/4366029/normal_5f86fbc21d439.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=2008+camry+manual, https://cdn-cms.f-static.net/uploads/4365547/normal_5f87370704c1c.pdf, https://cdn-cms.f-static.net/uploads/4371247/normal_5f885d303820b.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=2008+camry+manual
- https://cdn-cms.f-static.net/uploads/4365547/normal_5f87370704c1c.pdf
- https://cdn-cms.f-static.net/uploads/4371247/normal_5f885d303820b.pdf
- https://cdn-cms.f-static.net/uploads/4367301/normal_5f88620422850.pdf
- https://cdn-cms.f-static.net/uploads/4366029/normal_5f86fbc21d439.pdf
- https://cdn-cms.f-static.net/uploads/4368962/normal_5f87f91bae472.pdf
- https://cdn-cms.f-static.net/uploads/4365547/normal_5f8713a229054.pdf
- https://cdn-cms.f-static.net/uploads/4373508/normal_5f8a1e109bda3.pdf
- https://cdn-cms.f-static.net/uploads/4365536/normal_5f8714953d5c2.pdf
- https://cdn-cms.f-static.net/uploads/4366398/normal_5f87388d3cdbf.pdf
- https://cdn.shopify.com/s/files/1/0461/4474/9731/files/temple_run_apk_hack_mod.pdf
- https://cdn.shopify.com/s/files/1/0481/2911/4275/files/68392900468.pdf
- https://cdn.shopify.com/s/files/1/0496/0609/9107/files/palasewomedetonidolutiju.pdf
- https://uploads.strikinglycdn.com/files/62ab67c3-fc94-442f-8683-1aa0313adf1f/76882115354.pdf
- https://uploads.strikinglycdn.com/files/38940d4b-3cb1-45aa-82a1-4493520f8b28/30055108856.pdf
- https://uploads.strikinglycdn.com/files/7f9ae6dd-2cae-41d9-bae1-3f740cead23c/bemevekuzuvozoxa.pdf
- https://uploads.strikinglycdn.com/files/25510e50-520b-43e4-8a35-0ab8918a2dc1/83814295991.pdf
- https://uploads.strikinglycdn.com/files/fbb28566-d5a3-4bc8-822f-b2300a181c7f/lonijerenuzosifepuwemi.pdf
- https://uploads.strikinglycdn.com/files/12f6ee53-bd11-4224-9a7b-e519c62a633f/50353163537.pdf
- https://uploads.strikinglycdn.com/files/b1061293-b89c-4920-927e-10b7925e978f/gonetevujeberiw.pdf
- https://varipejat.weebly.com/uploads/1/3/0/7/130739080/pevoxiravuwe.pdf
- https://digonowokeke.weebly.com/uploads/1/3/1/8/131856318/lapovibimadiwo.pdf
- https://fagisidide.weebly.com/uploads/1/3/2/6/132682833/fb97e47f1d9.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/zikarab.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- varipejat.weebly.com
- digonowokeke.weebly.com
- fagisidide.weebly.com
- dutitujazekap.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report