SUSPICIOUS — 69051893524.pdf
SUSPICIOUS — 69051893524.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a445b5bbbea02092af32eea6fb5d413c6d6d049f6a272264e0403ee636948ed4 - SHA-1:
051f8875e33c16263a1fefe9e3bfce53e9a37052 - MD5:
b63449a119d7daa46e6b3b92b361a9a4 - ssdeep:
1536:qGF3Bw9db+H1q5+EnHckvnXnHWRVDlcl:TF329dS+pHck/nsVDE - TLSH:
T19C339DF3506BDE8CBB869B036DF60459240AD78C712397A0548CBB2CC5B86FD7E61960 - Submitted as: 69051893524.pdf
- File type: pdf · Size: 51737 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/98a96af6-9297-4e0a-a506-186aff4fa656/gedafujilimeravibigomajew.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=download+kisscartoon+apk, https://uploads.strikinglycdn.com/files/98a96af6-9297-4e0a-a506-186aff4fa656/gedafujilimeravibigomajew.pdf, https://cdn-cms.f-static.net/uploads/4383917/normal_5f8f699ea8dad.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=download+kisscartoon+apk
- https://uploads.strikinglycdn.com/files/98a96af6-9297-4e0a-a506-186aff4fa656/gedafujilimeravibigomajew.pdf
- https://cdn-cms.f-static.net/uploads/4383917/normal_5f8f699ea8dad.pdf
- https://cdn-cms.f-static.net/uploads/4421780/normal_5f9801d5854fa.pdf
- https://cdn-cms.f-static.net/uploads/4385633/normal_5f8ebd61c60e2.pdf
- https://cdn-cms.f-static.net/uploads/4412996/normal_5f9bc38d6a12c.pdf
- https://cdn-cms.f-static.net/uploads/4365634/normal_5f91eb8a441f8.pdf
- https://cdn-cms.f-static.net/uploads/4378425/normal_5f996be02d180.pdf
- https://uploads.strikinglycdn.com/files/592c8151-aaa9-405a-befd-732c60519877/zisid.pdf
- https://uploads.strikinglycdn.com/files/66cdccd3-748d-40fe-8c41-c1d20ba7cc4b/dazomusu.pdf
- https://cdn-cms.f-static.net/uploads/4373239/normal_5f9c4892c9836.pdf
- https://cdn-cms.f-static.net/uploads/4387219/normal_5f8e8472381f7.pdf
- https://cdn-cms.f-static.net/uploads/4381988/normal_5f8bd8526fbcc.pdf
- https://cdn-cms.f-static.net/uploads/4381082/normal_5f9c99ad12bf2.pdf
- https://cdn-cms.f-static.net/uploads/4378153/normal_5f9b43c13d888.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report