SUSPICIOUS — 92875648867.pdf
SUSPICIOUS — 92875648867.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
89cc1fce980a0a9b440f987f440fcfb2575f012ceb7271a58cef092125f78bca - SHA-1:
16fba140ff59dab0d2079b35c97af20b98f2e534 - MD5:
ba3641c375cbb5b83e0156d8b1bdd8c7 - ssdeep:
768:CgGzpDG+vxMyob5NAfuCmSuLAzEVAMSxYOP4aaK/cIukNeBZ:fGFKS6YGCPuLMEyMElP4wlukNeBZ - TLSH:
T1BF338DF31887CD8C7AC6AF47AEA60059618EC78D712697A015DCBB2CC47CABC7D50960 - Submitted as: 92875648867.pdf
- File type: pdf · Size: 51640 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/6f1d1e47-8383-4136-9eba-086c3b9fcf99/11892045738.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=autumn+leaves+chords+pdf, https://uploads.strikinglycdn.com/files/6f1d1e47-8383-4136-9eba-086c3b9fcf99/11892045738.pdf, https://uploads.strikinglycdn.com/files/a24efc72-5c6b-4810-aad6-53787db73ef2/gamimiwezixebo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=autumn+leaves+chords+pdf
- https://uploads.strikinglycdn.com/files/6f1d1e47-8383-4136-9eba-086c3b9fcf99/11892045738.pdf
- https://uploads.strikinglycdn.com/files/a24efc72-5c6b-4810-aad6-53787db73ef2/gamimiwezixebo.pdf
- https://uploads.strikinglycdn.com/files/7c3747f4-491a-4d8d-b6c1-7b4c4cba073e/88930976111.pdf
- https://uploads.strikinglycdn.com/files/ff4443cf-e961-445d-b26f-978af2b82cad/foleto.pdf
- https://uploads.strikinglycdn.com/files/1962d979-9cf7-4a3b-a40e-6eb380191306/fowaporo.pdf
- https://uploads.strikinglycdn.com/files/2735c4f3-ab19-4121-b89d-4ba6af18a0a0/64183578897.pdf
- https://uploads.strikinglycdn.com/files/6ba386a3-2f8b-473f-81dd-c5166218a616/45698517943.pdf
- https://uploads.strikinglycdn.com/files/f9735719-2ae2-4f69-a974-892c5d7ade2a/dojegokag.pdf
- https://uploads.strikinglycdn.com/files/5bf14924-3918-4f1b-a089-5221669abce3/peketafe.pdf
- https://uploads.strikinglycdn.com/files/32fc2da4-d209-4798-9a66-8c4a1a3ddab6/12545416796.pdf
- https://uploads.strikinglycdn.com/files/90bb2487-e459-4ff3-945f-bee447e5b8d9/xotesirawegemuxogeliv.pdf
- https://uploads.strikinglycdn.com/files/a15e6ef7-0d1f-4463-b5ed-6186f18a4deb/furunusejukubibakaxuf.pdf
- https://uploads.strikinglycdn.com/files/759d58f0-1f99-4297-bead-a8083a0b3be3/78579455394.pdf
- https://uploads.strikinglycdn.com/files/3c99f145-7f60-4c81-b8c1-12450cf09118/figidizuradiru.pdf
- https://uploads.strikinglycdn.com/files/1821f08d-043e-45c1-8270-6534d5930c8f/difiketo.pdf
- https://uploads.strikinglycdn.com/files/0fb937ba-b11d-4259-b214-8f43c4c37ad9/24235954997.pdf
- https://uploads.strikinglycdn.com/files/ed307e1d-11c9-4b66-9cd2-2f49935a37cd/19328023851.pdf
- https://uploads.strikinglycdn.com/files/41980033-0318-4b2a-954a-b6cd5809eb85/7042872094.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report