SUSPICIOUS — 29575156623.pdf
SUSPICIOUS — 29575156623.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7067b2ee1a3eccc49ed5ff852571a2b34ba1b89bb0ec3c787603d995895f002b - SHA-1:
33f2c6db1957dafcef18cc13949f031d4f8b116a - MD5:
902dc2325dacef71195a12e07f316260 - ssdeep:
768:DgGzpDUu9ueGQVc8BPL2beaodVuWk4NfHcVJ32zIxlcH:8GFoFFlbCrMWlvcV4zIxlcH - TLSH:
T145339EF351A7DD4C794AEB03AEBB641D604AD6486073E66445CC3B6DC4B86BE3E00E60 - Submitted as: 29575156623.pdf
- File type: pdf · Size: 48038 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/7885cbce-cab1-4c73-948a-a9dedf1e2e6e/16423868264.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=pie+chart+worksheets+6th+grade, https://uploads.strikinglycdn.com/files/7885cbce-cab1-4c73-948a-a9dedf1e2e6e/16423868264.pdf, https://uploads.strikinglycdn.com/files/b395e487-7870-48d2-bd4d-528d1441c8ef/lalasopux.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=pie+chart+worksheets+6th+grade
- https://uploads.strikinglycdn.com/files/7885cbce-cab1-4c73-948a-a9dedf1e2e6e/16423868264.pdf
- https://uploads.strikinglycdn.com/files/b395e487-7870-48d2-bd4d-528d1441c8ef/lalasopux.pdf
- https://uploads.strikinglycdn.com/files/6dc6fe7f-65c6-4c70-b5ee-af3a44cd8214/kegababujirivenelovaje.pdf
- https://uploads.strikinglycdn.com/files/a8c38513-b015-4048-8448-c2bddee6d306/51416957721.pdf
- https://uploads.strikinglycdn.com/files/40477e5b-fd78-4f7b-b184-8cf7ce18624b/kojukavogiketavemul.pdf
- https://uploads.strikinglycdn.com/files/0f2b6428-86e1-4fa1-9449-3a5727c6fe4f/lasezijirif.pdf
- https://uploads.strikinglycdn.com/files/93b7d2c2-ad6c-4aa6-9714-5e84402019a0/kanezivozutafitip.pdf
- https://uploads.strikinglycdn.com/files/e0fcb62c-8786-4bf3-9326-6a268b69bc18/38143527502.pdf
- https://uploads.strikinglycdn.com/files/c7ff0bb1-a3d8-4ec3-bfb7-2148e09684fc/96156965763.pdf
- https://uploads.strikinglycdn.com/files/fbddbcf7-053c-4d6f-a70a-08187f416538/90234542479.pdf
- https://uploads.strikinglycdn.com/files/92f450de-24ce-4dd3-b022-752af8ec174d/podejegow.pdf
- https://uploads.strikinglycdn.com/files/61a303a4-45b2-4a41-bd0c-33343caeadf6/15072803341.pdf
- https://site-1042821.mozfiles.com/files/1042821/41189979626.pdf
- https://site-1039775.mozfiles.com/files/1039775/vabekesazexa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1042821.mozfiles.com
- site-1039775.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report