SUSPICIOUS — 73145625067.pdf
SUSPICIOUS — 73145625067.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9d7fd58e603643d49552b56878ec216e527c3e06786b302dab193925f8ac5ff4 - SHA-1:
e4ea3af788ef147ab80818e2be05d0a461f6004b - MD5:
f2ed3dcda187bad777822e205d360a51 - ssdeep:
768:LgGzpDgpP9TpZH/Zu5U7XBUuHVC9A5gr+2fNAC8678s36JFfT:0GFUpPj6mmuHeqgr+cqJ/JFb - TLSH:
T148319EF35037EC8CBA8A6F076EA704589145C78C6127976095CC3B2DD8B8AFDBE10961 - Submitted as: 73145625067.pdf
- File type: pdf · Size: 40487 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/9509e055-8f19-4b2d-bd58-ff3e6c3e0687/mudimotamenirejupuz.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=villanueva+corporation+law+pdf, https://site-1042875.mozfiles.com/files/1042875/vuzodomozube.pdf, https://site-1043599.mozfiles.com/files/1043599/xuvewodi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=villanueva+corporation+law+pdf
- https://site-1042875.mozfiles.com/files/1042875/vuzodomozube.pdf
- https://site-1043599.mozfiles.com/files/1043599/xuvewodi.pdf
- https://site-1042013.mozfiles.com/files/1042013/28354265143.pdf
- https://uploads.strikinglycdn.com/files/9509e055-8f19-4b2d-bd58-ff3e6c3e0687/mudimotamenirejupuz.pdf
- https://uploads.strikinglycdn.com/files/31b813bf-94fc-4298-af05-045352268558/maxajukise.pdf
- https://uploads.strikinglycdn.com/files/4d717c2e-8238-4c2d-ab29-c6a595ff446f/fonovo.pdf
- https://uploads.strikinglycdn.com/files/1f62e573-4576-437e-b6b3-d172d3feb079/ximewotijawog.pdf
- https://site-1043215.mozfiles.com/files/1043215/68735834695.pdf
- https://site-1039167.mozfiles.com/files/1039167/5188319689.pdf
- https://site-1043686.mozfiles.com/files/1043686/jurirazawoniwamo.pdf
- https://cdn.shopify.com/s/files/1/0435/3264/8602/files/you_can_heal_your_body_in_marathi.pdf
- https://cdn.shopify.com/s/files/1/0481/8970/2301/files/central_rivers_aea_clear_lake_iowa.pdf
- https://cdn.shopify.com/s/files/1/0436/1306/1277/files/90613167678.pdf
- https://cdn.shopify.com/s/files/1/0476/4169/0278/files/fipagufapibofewabaxopo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1042875.mozfiles.com
- site-1043599.mozfiles.com
- site-1042013.mozfiles.com
- uploads.strikinglycdn.com
- site-1043215.mozfiles.com
- site-1039167.mozfiles.com
- site-1043686.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report