SUSPICIOUS — 35017113801.pdf
SUSPICIOUS — 35017113801.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6ef4786cc5078408e0c621ca7cb9b7518bb3de82f7e78241861a94ffd23a6044 - SHA-1:
c5eac541705316bd5783d65bcdf9b94ed0c66e67 - MD5:
ae0d0e6a7c160468a6981d99cef20bfa - ssdeep:
768:bTgGzpDGpPAvPxNDwpmjcaKI20lbhWLGk8E6ZqJ:IGFypowsqIPlbhWqkwZqJ - TLSH:
T17F316DF310D3ED8CBA4B6B039EAB119A518AD3C99137D7A04488672DD07C6FD6E00A75 - Submitted as: 35017113801.pdf
- File type: pdf · Size: 39950 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/054f445a-18a6-432b-a9aa-1751bf4dd0d5/13842067974.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=fifa+14+ppsspp+download+android, https://uploads.strikinglycdn.com/files/054f445a-18a6-432b-a9aa-1751bf4dd0d5/13842067974.pdf, https://uploads.strikinglycdn.com/files/85db5f10-25b0-40c3-b3b6-5b4aeb8e1fff/87561213137.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=fifa+14+ppsspp+download+android
- https://uploads.strikinglycdn.com/files/054f445a-18a6-432b-a9aa-1751bf4dd0d5/13842067974.pdf
- https://uploads.strikinglycdn.com/files/85db5f10-25b0-40c3-b3b6-5b4aeb8e1fff/87561213137.pdf
- https://uploads.strikinglycdn.com/files/bb3cdbb9-3378-4372-8aca-fa98abf8d06c/58668403053.pdf
- https://uploads.strikinglycdn.com/files/9fb85e11-e5a8-4813-8f3f-b69a09c5b836/zagikabatiru.pdf
- https://uploads.strikinglycdn.com/files/ba264c78-a693-4f02-b85e-cf76d6c98a87/66211775925.pdf
- https://site-1043091.mozfiles.com/files/1043091/nefako.pdf
- https://site-1038884.mozfiles.com/files/1038884/zomasi.pdf
- https://site-1040293.mozfiles.com/files/1040293/foxuwidolipewapaluzafuda.pdf
- https://site-1039775.mozfiles.com/files/1039775/vabekesazexa.pdf
- https://cdn-cms.f-static.net/uploads/4367927/normal_5f875c6449dc7.pdf
- https://cdn-cms.f-static.net/uploads/4366048/normal_5f874a521656f.pdf
- https://cdn-cms.f-static.net/uploads/4365539/normal_5f87028f4a7b3.pdf
- https://site-1036699.mozfiles.com/files/1036699/povipawixedo.pdf
- https://site-1043519.mozfiles.com/files/1043519/3308430326.pdf
- https://site-1039147.mozfiles.com/files/1039147/lawoxiwapelab.pdf
- https://site-1039283.mozfiles.com/files/1039283/58815542265.pdf
- https://site-1042007.mozfiles.com/files/1042007/15648472835.pdf
- https://uploads.strikinglycdn.com/files/f14a01a8-758d-4719-95e7-314507b2afea/14493443503.pdf
- https://uploads.strikinglycdn.com/files/24e3fa1f-30ae-43df-a303-f7986a5b768b/57098055997.pdf
- https://uploads.strikinglycdn.com/files/44215857-e46e-4efc-acfd-5c1e760361e2/34473400551.pdf
- https://site-1041608.mozfiles.com/files/1041608/32085359997.pdf
- https://site-1043406.mozfiles.com/files/1043406/favifeto.pdf
- https://site-1043115.mozfiles.com/files/1043115/11811776430.pdf
- https://site-1042106.mozfiles.com/files/1042106/9183607110.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1043091.mozfiles.com
- site-1038884.mozfiles.com
- site-1040293.mozfiles.com
- site-1039775.mozfiles.com
- cdn-cms.f-static.net
- site-1036699.mozfiles.com
- site-1043519.mozfiles.com
- site-1039147.mozfiles.com
- site-1039283.mozfiles.com
- site-1042007.mozfiles.com
- site-1041608.mozfiles.com
- site-1043406.mozfiles.com
- site-1043115.mozfiles.com
- site-1042106.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report