SUSPICIOUS — 46827351780.pdf
SUSPICIOUS — 46827351780.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
70e55f9028647694c20a03b4730416db59d3686661d98ba794b12b04dd56cc3b - SHA-1:
1515da6415d82f99ede772a4b75bdda8d3238bf0 - MD5:
594ae6c42f726d483f98de77695186ae - ssdeep:
768:qgGzpDS1Om5fVlxZ1PoPl963z6qZHanwGhVOr:3GF2HfVlhPobA6qVywEVOr - TLSH:
T11731AFF311ABEE8D79C76F076DBA1159615AC74C3022A6B45088B72DC8B82FC6E00B51 - Submitted as: 46827351780.pdf
- File type: pdf · Size: 39638 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://jekuvole.chirpytravels.com/uploads/1/3/2/6/132680831/wawerevilabewu.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=lagrima+piano+manual, http://jekuvole.chirpytravels.com/uploads/1/3/2/6/132680831/wawerevilabewu.pdf, http://files.taranakiequestrianjumping.com/uploads/1/3/1/6/131637108/mukafikinorovof.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=lagrima+piano+manual
- http://jekuvole.chirpytravels.com/uploads/1/3/2/6/132680831/wawerevilabewu.pdf
- http://files.taranakiequestrianjumping.com/uploads/1/3/1/6/131637108/mukafikinorovof.pdf
- http://files.vastuhealingarts.com/uploads/1/3/0/8/130874129/ritikamaviteg.pdf
- http://gejebiru.hypershft.com/uploads/1/3/1/3/131380005/novonafe.pdf
- http://files.sjcoescience.org/uploads/1/3/1/4/131409794/c780c4b8d.pdf
- https://uploads.strikinglycdn.com/files/d107d2be-a0ea-4695-a2de-70c74102a51d/47087230453.pdf
- https://uploads.strikinglycdn.com/files/09711390-309f-49d2-8995-c8078b24d2ae/sujafusegikuvoxevitusajen.pdf
- https://uploads.strikinglycdn.com/files/2f135386-8da7-4e8a-b8aa-c100de14ac27/xidaligisidozirisip.pdf
- https://uploads.strikinglycdn.com/files/5fd95e60-1165-46f2-9b24-2f619b00298c/bifitumawotolumolozituj.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- jekuvole.chirpytravels.com
- files.taranakiequestrianjumping.com
- files.vastuhealingarts.com
- gejebiru.hypershft.com
- files.sjcoescience.org
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report