SUSPICIOUS — 33687501099.pdf
SUSPICIOUS — 33687501099.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ae04f73dbe21b1c54898091dba492e58f3499e4a6f270cf9c0d5ab739444a2be - SHA-1:
c498179823036cfca0386106b522a3278d0cdc4a - MD5:
5c732120d111aae1ebb1ceff1d5fc607 - ssdeep:
768:NgGzpDRpHHAikZvmV8d6pMm1gMqvgHRCcfa25FbmG:uGF1pseWdywM5xnfVoG - TLSH:
T1332F8DF340A7ED8D2A8BAB836DE601441246C6CD7133A7A054D97B7CC4782BDBF41962 - Submitted as: 33687501099.pdf
- File type: pdf · Size: 34966 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/5f3c059c-3b09-4c21-a336-d139d6753bfa/karerefawi.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=libro+instalaciones+electricas+carlos+mario+diez, https://site-1043832.mozfiles.com/files/1043832/80074698147.pdf, https://site-1036786.mozfiles.com/files/1036786/rabajavis.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=libro+instalaciones+electricas+carlos+mario+diez
- https://site-1043832.mozfiles.com/files/1043832/80074698147.pdf
- https://site-1036786.mozfiles.com/files/1036786/rabajavis.pdf
- https://site-1048482.mozfiles.com/files/1048482/37803018909.pdf
- https://site-1039733.mozfiles.com/files/1039733/sotipigomutukunuvol.pdf
- https://site-1037120.mozfiles.com/files/1037120/rigegopunewojepuji.pdf
- https://site-1042990.mozfiles.com/files/1042990/36637950771.pdf
- https://cdn.shopify.com/s/files/1/0463/9552/3227/files/91795599668.pdf
- https://cdn.shopify.com/s/files/1/0432/9072/2454/files/getugalugupurijinareb.pdf
- https://cdn.shopify.com/s/files/1/0439/1370/7688/files/58519126969.pdf
- https://cdn.shopify.com/s/files/1/0435/7704/9247/files/meet_the_parents_script.pdf
- https://uploads.strikinglycdn.com/files/5f3c059c-3b09-4c21-a336-d139d6753bfa/karerefawi.pdf
- https://uploads.strikinglycdn.com/files/6e8c1e17-6427-4267-bdc6-f3f21733f1e5/10812029932.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1043832.mozfiles.com
- site-1036786.mozfiles.com
- site-1048482.mozfiles.com
- site-1039733.mozfiles.com
- site-1037120.mozfiles.com
- site-1042990.mozfiles.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report