SUSPICIOUS — 66040369885.pdf
SUSPICIOUS — 66040369885.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9cd1a8700dbc50e65c79061fd79cdcdbe3889c59dea81d3baf85b28cb062281a - SHA-1:
3f6b231eb7ecaacb12c2aa0a2c26ffbf54e19c9a - MD5:
a217a4372f8f5987972a0197844467e7 - ssdeep:
384:AsFlS3K6XgKV7cAgdOpW+0V4ZFKYQZhJ5BzHlCbVHxQDS5guUnCUSpiBe8Yq4Qi7:wgGzpDAIEpJBzHUHij10iBdCXL7Bkq - TLSH:
T109308DF31067ED4DBA8AAB07EDF61058518AC3887122C770488C7B6E95BC6BDBD00861 - Submitted as: 66040369885.pdf
- File type: pdf · Size: 36168 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/fbcc896b-15b0-4f75-ad2d-1098195cd262/39682472758.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=mitosis+and+meiosis+quiz+pdf, https://site-1036909.mozfiles.com/files/1036909/dukiwokegowenolapem.pdf, https://site-1040134.mozfiles.com/files/1040134/76259222564.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=mitosis+and+meiosis+quiz+pdf
- https://site-1036909.mozfiles.com/files/1036909/dukiwokegowenolapem.pdf
- https://site-1040134.mozfiles.com/files/1040134/76259222564.pdf
- https://site-1037233.mozfiles.com/files/1037233/9963165125.pdf
- https://site-1036886.mozfiles.com/files/1036886/denikepel.pdf
- https://uploads.strikinglycdn.com/files/fbcc896b-15b0-4f75-ad2d-1098195cd262/39682472758.pdf
- https://uploads.strikinglycdn.com/files/111d60ed-8ea9-4830-ac1a-b16fabe1b4fc/mifakizivibavokuxute.pdf
- https://uploads.strikinglycdn.com/files/74b0e9e5-11c2-43bf-9b0e-7cfb921c95ea/43949580665.pdf
- https://uploads.strikinglycdn.com/files/0cc348cf-1aab-41fa-b842-e3a94dbdbcda/donolas.pdf
- https://uploads.strikinglycdn.com/files/1682ad8c-439d-476b-b6c9-296f366febe9/44514609925.pdf
- https://uploads.strikinglycdn.com/files/03536d5d-11eb-498e-be73-30cfa154bc5e/11303787210.pdf
- https://uploads.strikinglycdn.com/files/0ca63954-dd3b-4f6e-bd0e-5d942e50af83/perewa.pdf
- https://uploads.strikinglycdn.com/files/149d30da-a570-4881-bf86-02a00c5d0a3e/goxove.pdf
- https://uploads.strikinglycdn.com/files/d6ec8973-b3c2-450f-9856-d9277e93901f/389616630.pdf
- https://uploads.strikinglycdn.com/files/cafcf2f3-f175-481f-a5c4-13e9f1a070f3/lufidaru.pdf
- https://site-1036685.mozfiles.com/files/1036685/zufapi.pdf
- https://site-1036941.mozfiles.com/files/1036941/musexonenalagepov.pdf
- https://site-1036879.mozfiles.com/files/1036879/vadutixira.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1036909.mozfiles.com
- site-1040134.mozfiles.com
- site-1037233.mozfiles.com
- site-1036886.mozfiles.com
- uploads.strikinglycdn.com
- site-1036685.mozfiles.com
- site-1036941.mozfiles.com
- site-1036879.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report