SUSPICIOUS — 72967334890.pdf
SUSPICIOUS — 72967334890.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9d29c84a608c602e13b78f46099a691678c7f2ac95753486950e17857d9712db - SHA-1:
1dedf0ff16c5ed561f669c7d0d7dbe05ad5b1046 - MD5:
32c91db0a6c9634df08f48c97e986a78 - ssdeep:
1536:7GFgKVRWRR4RzXXjUsNTD3ybwlwNutcLUKWA:aFgKVMCzrNybXQcw+ - TLSH:
T1CE37D0F35097DC8C6A86AB07BEE614295055DB48A133E7A858DCBB3CD07C3AD2F11A11 - Submitted as: 72967334890.pdf
- File type: pdf · Size: 69735 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://nefodo.lphschem.com/uploads/1/3/2/6/132682663/2679044.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=basic+automotive+repair+pdf, http://files.mochiboutique.com/uploads/1/3/0/7/130740252/3945569.pdf, http://nefodo.lphschem.com/uploads/1/3/2/6/132682663/2679044.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=basic+automotive+repair+pdf
- http://files.mochiboutique.com/uploads/1/3/0/7/130740252/3945569.pdf
- http://nefodo.lphschem.com/uploads/1/3/2/6/132682663/2679044.pdf
- http://files.theunlimiteddreamer.com/uploads/1/3/2/6/132681038/mejebolofosanok_dubiw_gewuwagiw_gujijevon.pdf
- https://site-1036834.mozfiles.com/files/1036834/56448891176.pdf
- https://site-1036828.mozfiles.com/files/1036828/81203739162.pdf
- http://buzosu.pdcscuba.com/uploads/1/3/0/7/130776298/vobemuzu.pdf
- http://files.hubert-music.com/uploads/1/3/1/4/131406811/padusidezi.pdf
- http://xibutuvij.asrar103.com/uploads/1/3/1/3/131379724/leraduf-ginabujojif-rawemetaxoxef.pdf
- http://files.lingalonga.net/uploads/1/3/1/8/131857650/totuzijo_joberekod.pdf
- https://uploads.strikinglycdn.com/files/fd34d444-3231-4b88-9ba0-02fd48cf7fca/40331200315.pdf
- https://uploads.strikinglycdn.com/files/af9f2517-9143-416a-b249-52e935a5a60e/pemifuwupuwabukitepo.pdf
- https://uploads.strikinglycdn.com/files/5c2aee64-8871-4fc7-aa90-531ec2d09cf0/2711723425.pdf
- https://uploads.strikinglycdn.com/files/8384d2c2-81f6-4345-b771-bfbd86a75540/zonogaga.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- files.mochiboutique.com
- nefodo.lphschem.com
- files.theunlimiteddreamer.com
- site-1036834.mozfiles.com
- site-1036828.mozfiles.com
- buzosu.pdcscuba.com
- files.hubert-music.com
- xibutuvij.asrar103.com
- files.lingalonga.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report