SUSPICIOUS — 52248980867.pdf
SUSPICIOUS — 52248980867.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
72990e580b5dfbd9b0e58aa440842964793dfaf9c2c2a0b51c57aace01e0103c - SHA-1:
40bfc0f680157f072fbf1ca5cfa35db5250d5b94 - MD5:
ec3bcbe8c7f87d22a1fd124aea26cde2 - ssdeep:
768:qYgGzpDzpba+sTQrJ3ds+jceApaVE9nB/9bDCg+GTDvMZTGLt:aGFfpDZrJ3dHNAsYB5DCg+lGLt - TLSH:
T16E328DF354DBDD0CBA87AB07AEFA1094958EC38C2162936054887B3DD4BC5FC6E11A61 - Submitted as: 52248980867.pdf
- File type: pdf · Size: 47218 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/094a8445-d2c4-43f1-bfdb-c5355851bd17/rorefomevomenupoko.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=gta+vice+city+cheater+androidpur, https://uploads.strikinglycdn.com/files/094a8445-d2c4-43f1-bfdb-c5355851bd17/rorefomevomenupoko.pdf, https://uploads.strikinglycdn.com/files/e6db0520-ac79-4d3e-95d1-8ce085804d3f/80740332246.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=gta+vice+city+cheater+androidpur
- https://uploads.strikinglycdn.com/files/094a8445-d2c4-43f1-bfdb-c5355851bd17/rorefomevomenupoko.pdf
- https://uploads.strikinglycdn.com/files/e6db0520-ac79-4d3e-95d1-8ce085804d3f/80740332246.pdf
- https://uploads.strikinglycdn.com/files/36d1a2a5-8410-4456-9f80-e18d88c16495/dofelogibud.pdf
- https://uploads.strikinglycdn.com/files/839c50e6-4d86-46a0-8efc-8cf32d0d0895/kiropemomesif.pdf
- https://uploads.strikinglycdn.com/files/ef6cc302-66f8-4358-8935-b5c074cc964e/95698535244.pdf
- https://uploads.strikinglycdn.com/files/5db4078f-aa93-4981-8b8f-15051c040128/59001406414.pdf
- https://uploads.strikinglycdn.com/files/6d06e88c-b28e-4200-a3c9-a7a92f58824b/25248342065.pdf
- https://uploads.strikinglycdn.com/files/f0972f62-afad-45ff-9e1d-e3cb36ab56df/50625636876.pdf
- https://uploads.strikinglycdn.com/files/22134bc7-8cbd-4fcd-97c5-6617636268c7/76396077428.pdf
- https://uploads.strikinglycdn.com/files/d61ad686-9845-4b5a-a443-010dab9512ef/doxitibeki.pdf
- https://site-1041489.mozfiles.com/files/1041489/49448361099.pdf
- https://site-1048288.mozfiles.com/files/1048288/xagesalof.pdf
- https://site-1043582.mozfiles.com/files/1043582/xozididekuwagokale.pdf
- https://site-1041583.mozfiles.com/files/1041583/balodatewusozijawa.pdf
- https://site-1039632.mozfiles.com/files/1039632/kipujanamajulif.pdf
- https://uploads.strikinglycdn.com/files/24f17fc0-60c4-44b9-a846-e6645f9dd757/65829696520.pdf
- https://uploads.strikinglycdn.com/files/8611fe27-565b-4c72-b5fb-a277f0686bef/75220084207.pdf
- https://uploads.strikinglycdn.com/files/44f20804-1e7e-4115-ad07-868dc65cfff8/96679728290.pdf
- https://uploads.strikinglycdn.com/files/2934ac45-af60-4060-9a62-57a19c92fbc0/fiwunarivadelav.pdf
- https://uploads.strikinglycdn.com/files/6e174932-b053-47d6-b5d6-b774cd743f1f/dorikisadu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1041489.mozfiles.com
- site-1048288.mozfiles.com
- site-1043582.mozfiles.com
- site-1041583.mozfiles.com
- site-1039632.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report