SUSPICIOUS — 92162530131.pdf
SUSPICIOUS — 92162530131.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9829ecfe3fe1332ef6e7a4253ac8b73a58791abde6f3566b3e6b3bc95959bb94 - SHA-1:
7af989eeaae6296b51b874e7edf20d64ca000c51 - MD5:
47f0cef428d8f745a8ad0c27ba906a72 - ssdeep:
1536:fGFRpPKikwIX3B5emswWRdQ8s/lDqJJHbCna2BD7LWmr5tx18WsBC6yc1qeFFV:OFRpewIBdWRdQ9/96bya2FWQtT8WL6y0 - TLSH:
T15B38D0B711A7ED88A5C6BF43AEBA10381149E74C71369BA065DC371DC47C3EEAE10621 - Submitted as: 92162530131.pdf
- File type: pdf · Size: 83192 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/73d22044-999d-4ed0-a2ee-af0df774be21/73151882466.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=does+the+skyrim+remastered+come+with+dlc, https://uploads.strikinglycdn.com/files/73d22044-999d-4ed0-a2ee-af0df774be21/73151882466.pdf, https://uploads.strikinglycdn.com/files/6bfa250d-540b-4b45-828b-148c0c8175c4/vineni.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=does+the+skyrim+remastered+come+with+dlc
- https://uploads.strikinglycdn.com/files/73d22044-999d-4ed0-a2ee-af0df774be21/73151882466.pdf
- https://uploads.strikinglycdn.com/files/6bfa250d-540b-4b45-828b-148c0c8175c4/vineni.pdf
- https://uploads.strikinglycdn.com/files/ec7a1c29-4d31-4f0e-982e-f1ed62bb2fbb/fasiwonugun.pdf
- https://site-1039672.mozfiles.com/files/1039672/25226729607.pdf
- https://site-1038527.mozfiles.com/files/1038527/wagewinefexolakesivobawov.pdf
- https://uploads.strikinglycdn.com/files/f1e2d1ca-0db1-432a-8b9e-2ea8cdce4811/xumaxeno.pdf
- https://uploads.strikinglycdn.com/files/3180369d-7327-428c-8c2a-64ec3e0be47e/67012533735.pdf
- https://uploads.strikinglycdn.com/files/0ed0aabf-01c2-420e-b253-c7fe3fd6303d/gokizogu.pdf
- https://uploads.strikinglycdn.com/files/0353e57b-35a1-4bfa-b2e0-c0bcb183ce19/dedelalotumiv.pdf
- https://cdn.shopify.com/s/files/1/0437/7503/3505/files/77081307726.pdf
- https://cdn.shopify.com/s/files/1/0266/8498/1436/files/piping_system_fundamentals.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1039672.mozfiles.com
- site-1038527.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report