SUSPICIOUS — 29046459139.pdf
SUSPICIOUS — 29046459139.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8c75c81a231213c46621c9a4529dc7f8d2af3590babb93dbf98e339c6689f8a5 - SHA-1:
17a431c129cc5385074762c1fdff07f998047462 - MD5:
5d7d171d3ffa5215bb1aa1910d3e8cff - ssdeep:
768:1gGzpDAA7jMQ8S3Eiv7FTWYz7fuzBGmX:mGF0zy3Eizxjz7fkGmX - TLSH:
T1EF32AEF740ABED8CBACB6F036DA611191455C38CB176967009D83BBDC87C6BD6E01920 - Submitted as: 29046459139.pdf
- File type: pdf · Size: 43431 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/dcc34511-b1e7-4f4b-8792-c1a9aac7a446/6515626140.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=chestionare+auto+2020+pdf, https://site-1043357.mozfiles.com/files/1043357/lazekusekatawojur.pdf, https://site-1043855.mozfiles.com/files/1043855/vomini.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=chestionare+auto+2020+pdf
- https://site-1043357.mozfiles.com/files/1043357/lazekusekatawojur.pdf
- https://site-1043855.mozfiles.com/files/1043855/vomini.pdf
- https://site-1038578.mozfiles.com/files/1038578/66753243747.pdf
- https://site-1036848.mozfiles.com/files/1036848/dusemuvazilawetonakalali.pdf
- https://site-1036693.mozfiles.com/files/1036693/mimewuzumixowavazugegug.pdf
- https://site-1037169.mozfiles.com/files/1037169/80541804655.pdf
- https://site-1044309.mozfiles.com/files/1044309/12484587640.pdf
- https://uploads.strikinglycdn.com/files/dcc34511-b1e7-4f4b-8792-c1a9aac7a446/6515626140.pdf
- https://uploads.strikinglycdn.com/files/76c996b5-9849-4a66-a0a6-61805399b9d7/7547753237.pdf
- https://uploads.strikinglycdn.com/files/93cbb7fd-8999-4591-a816-8ec9e7e8d307/basivamujadogujo.pdf
- https://uploads.strikinglycdn.com/files/557b5503-55ec-4842-aa87-cf88cdcf461d/98062418637.pdf
- https://uploads.strikinglycdn.com/files/3a41e4da-1ff0-4ac3-bdab-54a1df838f6e/mawazuwogiwiwutebonevuni.pdf
- https://uploads.strikinglycdn.com/files/9e8576f2-7377-4e61-938c-7c94a48723a8/rezazutumapivebaxuputowi.pdf
- https://uploads.strikinglycdn.com/files/037a24d6-0f0e-45d7-be2c-0f68fa15cf99/xudijemila.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1043357.mozfiles.com
- site-1043855.mozfiles.com
- site-1038578.mozfiles.com
- site-1036848.mozfiles.com
- site-1036693.mozfiles.com
- site-1037169.mozfiles.com
- site-1044309.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report