SUSPICIOUS — 59062445425.pdf
SUSPICIOUS — 59062445425.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8583ead9f2135ea9a605da31f19f31af1e54cd05fca0ea376d5321506b1d5166 - SHA-1:
c3b9573bb361961aa1e31b2e527949b31faa1c7c - MD5:
30aa9dbc7e49ebd114b82bbc32b8e777 - ssdeep:
768:ygGzpD8RknwcS0a0rjHvCk+v0h4eoK3sTokLI4RIFLZV:vGF4e/J+6dso1XFLZV - TLSH:
T127318DF750ABDE8C3E879B43ACB31164654AD6887133D3A4458C3A2CD9BC6AD7F11860 - Submitted as: 59062445425.pdf
- File type: pdf · Size: 42355 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/7fb882ea-9d99-4b80-89fa-98f62f7f4c74/48269771913.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=clasificacion+de+los+seres+vivos+segun+whittaker+pdf, https://uploads.strikinglycdn.com/files/7fb882ea-9d99-4b80-89fa-98f62f7f4c74/48269771913.pdf, https://uploads.strikinglycdn.com/files/1789d109-c087-4b26-a55e-b8f747d2e0cb/90098276843.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=clasificacion+de+los+seres+vivos+segun+whittaker+pdf
- https://uploads.strikinglycdn.com/files/7fb882ea-9d99-4b80-89fa-98f62f7f4c74/48269771913.pdf
- https://uploads.strikinglycdn.com/files/1789d109-c087-4b26-a55e-b8f747d2e0cb/90098276843.pdf
- https://uploads.strikinglycdn.com/files/5f53c691-3285-4295-a8d6-2a27c4dc8a11/xuvuxidodopedezad.pdf
- https://uploads.strikinglycdn.com/files/6eea14b1-cf75-4723-9ed2-aa7349ca300a/bapexololujavitem.pdf
- https://uploads.strikinglycdn.com/files/77fda588-7d00-47aa-9f65-b3eb558b893b/nezukenuverog.pdf
- https://uploads.strikinglycdn.com/files/32fc2da4-d209-4798-9a66-8c4a1a3ddab6/12545416796.pdf
- https://uploads.strikinglycdn.com/files/0fcb93b7-cf1a-4261-a464-142655d48b25/vojitekini.pdf
- https://uploads.strikinglycdn.com/files/b3d30470-0faa-419a-a826-38a2c0254913/86730527478.pdf
- https://cdn.shopify.com/s/files/1/0428/3056/1436/files/jemasaka.pdf
- https://cdn.shopify.com/s/files/1/0432/2865/9870/files/21844875502.pdf
- https://cdn.shopify.com/s/files/1/0435/3284/5207/files/sowimasomefefuwosojaxif.pdf
- https://cdn.shopify.com/s/files/1/0429/6540/1753/files/57018640631.pdf
- http://tijajak.njyf.org/uploads/1/3/0/7/130776487/ruminaxoruxinid.pdf
- http://files.boodlez.com/uploads/1/3/2/6/132695280/e336872bf35cc5.pdf
- http://gulozabo.mustangcreekcreations.com/uploads/1/3/1/6/131606490/nidoxezokisax.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- tijajak.njyf.org
- files.boodlez.com
- gulozabo.mustangcreekcreations.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report