SUSPICIOUS — satof.pdf
SUSPICIOUS — satof.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8663bebef95214e9e17300ddf527a9c090dacbcf873e8d71394e5ae33a65eca2 - SHA-1:
7e4b0594385c8d4a02c271dbe7e74b40338258c5 - MD5:
232956251b13f8f650cf6138e911bac8 - ssdeep:
768:smgGzpDa6Hbp6hWkJxfuhESBt9wuo/FuY45wAJJNc+c6ZJiDMQy0FGNd/Q:GGFOZWtt9wueKJJNc+7ZJiDJzFGNd/Q - TLSH:
T1AD339EF3409BDD4C768A9703A5FB1129A65BC28DA1339BA008CC376DD4BC67CBD60A51 - Submitted as: satof.pdf
- File type: pdf · Size: 47895 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/90d95456-b1d8-4ee4-a43f-d65701e75eaf/xovex.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=taco+bell+nutrition+crunchwrap+supreme+beef, https://cdn.shopify.com/s/files/1/0462/2237/7114/files/como_hacer_objetivos_especificos.pdf, https://cdn.shopify.com/s/files/1/0495/9738/2805/files/dimutofov.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=taco+bell+nutrition+crunchwrap+supreme+beef
- https://cdn.shopify.com/s/files/1/0462/2237/7114/files/como_hacer_objetivos_especificos.pdf
- https://cdn.shopify.com/s/files/1/0495/9738/2805/files/dimutofov.pdf
- https://cdn.shopify.com/s/files/1/0439/2294/8251/files/saladerokujaworirosoge.pdf
- https://cdn.shopify.com/s/files/1/0432/2784/0675/files/skmei_1142_manual_portugues.pdf
- https://cdn.shopify.com/s/files/1/0436/9884/7894/files/fivufesod.pdf
- https://uploads.strikinglycdn.com/files/90d95456-b1d8-4ee4-a43f-d65701e75eaf/xovex.pdf
- https://uploads.strikinglycdn.com/files/d3a088c2-15c3-4fe1-9d9f-a358cb3a719b/49801150242.pdf
- https://uploads.strikinglycdn.com/files/355e1afb-9514-4909-94e3-c00582f8974e/fipotonowuluguvunulotiwul.pdf
- https://uploads.strikinglycdn.com/files/ebf80e39-2089-41cc-96b2-49deb4c843a9/gimujidomirodama.pdf
- https://site-1037074.mozfiles.com/files/1037074/40126380217.pdf
- https://site-1039564.mozfiles.com/files/1039564/sunedujexotusofisuw.pdf
- https://site-1044015.mozfiles.com/files/1044015/bugevarolufuxori.pdf
- https://site-1037240.mozfiles.com/files/1037240/9117322127.pdf
- https://site-1038472.mozfiles.com/files/1038472/satubujanobuvedojobe.pdf
- https://uploads.strikinglycdn.com/files/58a51e83-2af5-4d26-b3fc-0bcdada84080/jukimuj.pdf
- https://uploads.strikinglycdn.com/files/922fa1cd-5e1b-4cc7-8cac-5341d31a3c3a/litajurif.pdf
- https://uploads.strikinglycdn.com/files/aa48973e-525d-4efd-b7fb-fd6aaebaf942/zoburanedigaborazaliwi.pdf
- https://uploads.strikinglycdn.com/files/c5710eb0-4666-4f75-9d4c-7b484bbfc4a2/tonutusaviwusunejazaxovot.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1037074.mozfiles.com
- site-1039564.mozfiles.com
- site-1044015.mozfiles.com
- site-1037240.mozfiles.com
- site-1038472.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report