SUSPICIOUS — 95991328466.pdf
SUSPICIOUS — 95991328466.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
99669672a660c4d03e85a139377a7ad38d0a40447c5219616a86f73f533790ea - SHA-1:
08ff7da470abfbd3726ca2834090b43038833973 - MD5:
6cb1840e9ab1bc48b59443c95727c0a3 - ssdeep:
768:lgGzpDfp/wOqR5OiTzoLX+vNHu4so3wABbEyqToraY7pGBBVAab9JPN+:2GFjp1mzDU4so3bqQT7UBBVAab9JPN+ - TLSH:
T1EC33AFF340A7ED8D7A8B6B87AEA3008D604AD68D7136935444C8772DC0BC6FE6F10A55 - Submitted as: 95991328466.pdf
- File type: pdf · Size: 49424 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/27404fce-21c1-4c55-ae1f-bb77de6c1150/82303114150.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=satran%25C3%25A7+geli%25C5%259Ftirme+kitaplar%25C4%25B1, https://uploads.strikinglycdn.com/files/c26b78d2-db48-40d3-a2a5-16a1d1be47e4/lasofejami.pdf, https://uploads.strikinglycdn.com/files/27404fce-21c1-4c55-ae1f-bb77de6c1150/82303114150.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=satran%25C3%25A7+geli%25C5%259Ftirme+kitaplar%25C4%25B1
- https://uploads.strikinglycdn.com/files/c26b78d2-db48-40d3-a2a5-16a1d1be47e4/lasofejami.pdf
- https://uploads.strikinglycdn.com/files/27404fce-21c1-4c55-ae1f-bb77de6c1150/82303114150.pdf
- https://uploads.strikinglycdn.com/files/1ce427f4-be50-4adf-85e9-6ad5058aaf6b/zelutubovematerodidat.pdf
- https://uploads.strikinglycdn.com/files/96f2689a-d1f4-4f29-873c-d9475b871f29/65731672176.pdf
- https://uploads.strikinglycdn.com/files/4c49fa71-12f4-4a36-b4e2-ff3b9a275a97/winenoledisomelu.pdf
- http://files.acas.us/uploads/1/3/0/7/130739369/kopovirawomirodove.pdf
- http://files.cookwithrayla.com/uploads/1/3/1/6/131606035/menovupojeso_tuzerajok.pdf
- http://files.macgameset.com/uploads/1/3/1/3/131379541/1405802.pdf
- http://files.cedarridgeupnorth.com/uploads/1/3/1/3/131384127/dagipikuju_tuwax.pdf
- http://bozifosen.pobny.com/uploads/1/3/2/6/132695569/38197.pdf
- http://files.3queenspublish.com/uploads/1/3/2/6/132682295/2163312.pdf
- http://files.ritchandyvette.com/uploads/1/3/1/6/131637419/manelawiro.pdf
- http://ramegini.corpuschristiconcretepros.com/uploads/1/3/0/7/130775545/tavaxigopigaj.pdf
- http://files.sarahtesolhub.com/uploads/1/3/0/9/130969922/5d8558ca2b8088.pdf
- http://jadex.tcujeffrieslab.com/uploads/1/3/0/8/130813668/3039394.pdf
- http://files.studioksandb.com/uploads/1/3/1/3/131398547/pesilemow.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- files.acas.us
- files.cookwithrayla.com
- files.macgameset.com
- files.cedarridgeupnorth.com
- bozifosen.pobny.com
- files.3queenspublish.com
- files.ritchandyvette.com
- ramegini.corpuschristiconcretepros.com
- files.sarahtesolhub.com
- jadex.tcujeffrieslab.com
- files.studioksandb.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report