SUSPICIOUS — 4599873625.pdf
SUSPICIOUS — 4599873625.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7445116e205c205522e12602d7a692c947dc1998a4c048ce209aa8fa03be9674 - SHA-1:
49e582e907c9b09448db27d3e0478b6265c487b5 - MD5:
5c3da55ae6e379e3343cc7c9d1d3255e - ssdeep:
768:OgGzpDxcStwmM9Q3/yOfjjuXGVAAZE6DfGf6m1jF1x2c6DNZ1SCVW445P/9:rGFlcDLy6hfGRDfGf6mLT2c6b1Sgn6PF - TLSH:
T19C339DF321A7DC8C3A8AAF53AEF710691146C3587132D6A055CD776CC4BC2BE6E10A91 - Submitted as: 4599873625.pdf
- File type: pdf · Size: 48008 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/f494f68b-e51e-4a97-b57c-0b7a708835ed/58262918014.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=windows+8.1+free+download+iso+64+bit, http://files.archives.uucsarasota.com/uploads/1/3/0/9/130969306/pulubaboz_jetupawukarij_jinimukatekidaw_puwapegases.pdf, http://gobulo.ywcahealthandfitness.org/uploads/1/3/2/6/132681481/d3d4075199.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=windows+8.1+free+download+iso+64+bit
- http://files.archives.uucsarasota.com/uploads/1/3/0/9/130969306/pulubaboz_jetupawukarij_jinimukatekidaw_puwapegases.pdf
- http://gobulo.ywcahealthandfitness.org/uploads/1/3/2/6/132681481/d3d4075199.pdf
- http://berovepib.woodeesri.com/uploads/1/3/1/6/131607062/9831530.pdf
- http://guxukabi.asiarevivalcentre.org/uploads/1/3/1/6/131607662/41b473059ecacc.pdf
- https://uploads.strikinglycdn.com/files/f494f68b-e51e-4a97-b57c-0b7a708835ed/58262918014.pdf
- https://uploads.strikinglycdn.com/files/ac966094-657f-41ab-9aad-79ecada960c4/31299945821.pdf
- https://uploads.strikinglycdn.com/files/43ce7dac-bc02-4399-9677-60e1be0f8b8d/kutazesigufarulofopukojim.pdf
- https://uploads.strikinglycdn.com/files/5d3be060-aa24-464a-b8c7-177b96d22a24/telitejodasawewujiwa.pdf
- https://uploads.strikinglycdn.com/files/74c06dc8-57f9-4fa1-ba4b-58ce7c9552b3/jemopededoda.pdf
- https://uploads.strikinglycdn.com/files/db3e10a6-c71b-4598-8ba4-5a3da3ea52f1/sugiwaparitobuzikusiwi.pdf
- https://uploads.strikinglycdn.com/files/5e9139e6-a337-4cff-a173-31110361404b/92867255634.pdf
- https://cdn.shopify.com/s/files/1/0485/1030/4418/files/rugunuxopunamotujajexuxox.pdf
- https://cdn.shopify.com/s/files/1/0430/4447/0945/files/movititimuwifeguxi.pdf
- https://cdn.shopify.com/s/files/1/0433/2974/9145/files/kowuzudenijijavasoxi.pdf
- https://cdn.shopify.com/s/files/1/0439/0499/1400/files/marvel_contest_of_champions_units_hack_no_human_verification.pdf
- https://cdn.shopify.com/s/files/1/0482/3701/9288/files/development_of_atomic_theory_answer_key.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- files.archives.uucsarasota.com
- gobulo.ywcahealthandfitness.org
- berovepib.woodeesri.com
- guxukabi.asiarevivalcentre.org
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report