SUSPICIOUS — 20687282084.pdf
SUSPICIOUS — 20687282084.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
88d45ef5194f2a8e98e7e85462e9cddbd76276aafaef0997ed946e8022d05305 - SHA-1:
cc517f692897458e34a5f860a86364c7b3ed5a34 - MD5:
efb750a7514ae3ca0f00b83d61b6e65f - ssdeep:
768:4/gGzpDAspRilDOMjGjkMx3ezlq91O31Bu48o4kWh4sHFIhaOU:VGF1pRrn3ow91qu48XRWhaOU - TLSH:
T16833AEF36197EC8C7E8B5B436DEB162A404AC74CA132A69005C8376CD4FC6BD7E11962 - Submitted as: 20687282084.pdf
- File type: pdf · Size: 49086 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/ff224977-276e-41bc-b0a3-16fad58e1563/guderekeva.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=music+cutter+and+mixer+app+for+android, https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/d51d597141df676.pdf, https://buveziketi.weebly.com/uploads/1/3/1/3/131398526/64451afed5.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=music+cutter+and+mixer+app+for+android
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/d51d597141df676.pdf
- https://buveziketi.weebly.com/uploads/1/3/1/3/131398526/64451afed5.pdf
- https://vawotitalu.weebly.com/uploads/1/3/2/7/132710714/2332972.pdf
- https://uploads.strikinglycdn.com/files/ff224977-276e-41bc-b0a3-16fad58e1563/guderekeva.pdf
- https://uploads.strikinglycdn.com/files/a545fc24-d466-4616-b0be-4236b34612b7/xudofemifoferofuxoruri.pdf
- https://uploads.strikinglycdn.com/files/e3bd8288-9525-4e4b-9b2d-6ccccf43a3b9/vexatox.pdf
- https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/cb8148.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/1392291.pdf
- https://cdn.shopify.com/s/files/1/0496/8067/9064/files/45885515146.pdf
- https://cdn.shopify.com/s/files/1/0439/4532/8808/files/fumejarexetozomakowa.pdf
- https://cdn.shopify.com/s/files/1/0495/9548/2261/files/dense_irregular_connective_tissue_found_on_the_surface_of_a_long_bone.pdf
- https://cdn.shopify.com/s/files/1/0432/5097/4888/files/my_cousin_rachel_epub_download.pdf
- https://uploads.strikinglycdn.com/files/f29885d2-9877-404c-8c4f-5d0df0d0d2cd/senazerat.pdf
- https://uploads.strikinglycdn.com/files/9c7ca2cd-bb2b-48ef-8616-0f3ae06f7b7d/wevurujudunada.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/5648329.pdf
- https://pibazafefudo.weebly.com/uploads/1/3/0/7/130776509/8198697.pdf
- https://polabufasol.weebly.com/uploads/1/3/2/8/132814050/ponudetebaj.pdf
- https://kasukironumasex.weebly.com/uploads/1/3/1/4/131454791/javotedel-wibuweja-jufutimofekeliv-xaleb.pdf
- https://nobinetezo.weebly.com/uploads/1/3/0/9/130969761/gexipogug.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- jakedekokobara.weebly.com
- buveziketi.weebly.com
- vawotitalu.weebly.com
- uploads.strikinglycdn.com
- besiwalufeg.weebly.com
- xojerajap.weebly.com
- cdn.shopify.com
- fijojonibiw.weebly.com
- pibazafefudo.weebly.com
- polabufasol.weebly.com
- kasukironumasex.weebly.com
- nobinetezo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report