SUSPICIOUS — 19801085550.pdf
SUSPICIOUS — 19801085550.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8786ef6f6e10f223b7fc9aeaa83f4619b87babc856f8060a424d3fe30c3612fa - SHA-1:
b09f0db0254b2f90ecc9bef5c14cdd3889336c22 - MD5:
e39d48e2045b6407ba13bf88cf4a24c1 - ssdeep:
768:agGzpDgLIsok61o5w89KI6XFpKqBpvJMfe2ZoyjSGfz5baIr4jybRl1TBX:HGFM617BpOG2ZoY/fzdatjEnTBX - TLSH:
T10A318DF31067EDCC6A8BAB43ADE201596145D6887132A27449C8B73CD87C6FDBF01A60 - Submitted as: 19801085550.pdf
- File type: pdf · Size: 41622 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://jupefusa.dphsart.org/uploads/1/3/0/7/130739344/9073402.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=causas+de+candidiasis+esofagica+pdf, http://risikazo.abdullah-francis.com/uploads/1/3/1/4/131438667/wuwadezizal.pdf, http://fosowimud.stpaulscollingswood.com/uploads/1/3/1/6/131606938/1846012.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=causas+de+candidiasis+esofagica+pdf
- http://risikazo.abdullah-francis.com/uploads/1/3/1/4/131438667/wuwadezizal.pdf
- http://fosowimud.stpaulscollingswood.com/uploads/1/3/1/6/131606938/1846012.pdf
- http://kamevana.ctascet.org/uploads/1/3/1/3/131379732/9176763.pdf
- https://cdn.shopify.com/s/files/1/0485/8786/6272/files/directv_channel_guide_to_be_announced.pdf
- https://cdn.shopify.com/s/files/1/0433/9240/1566/files/wamatojedapanulota.pdf
- https://cdn.shopify.com/s/files/1/0440/6162/2437/files/43195398398.pdf
- http://vufozoz.alex-chien.com/uploads/1/3/0/8/130814328/gavuvefo.pdf
- http://mizegoj.semainesecuriteagricole.ca/uploads/1/3/1/8/131871816/pemurib.pdf
- http://jupefusa.dphsart.org/uploads/1/3/0/7/130739344/9073402.pdf
- https://cdn.shopify.com/s/files/1/0433/1431/5422/files/contacting_the_iphone_software_update_server.pdf
- https://cdn.shopify.com/s/files/1/0429/6150/2362/files/bekokogopitipagajotureli.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/26225030347.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- risikazo.abdullah-francis.com
- fosowimud.stpaulscollingswood.com
- kamevana.ctascet.org
- cdn.shopify.com
- vufozoz.alex-chien.com
- mizegoj.semainesecuriteagricole.ca
- jupefusa.dphsart.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report