SUSPICIOUS — 59344786927.pdf
SUSPICIOUS — 59344786927.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
af8960e04e9ee6192c401d5dcf4bf3b20b4a6fcd6abe422d6c981de761158c91 - SHA-1:
ebec4ea5b158b8af4e2643ed57a22828811a0b87 - MD5:
bc11123ae1171220489fcf9bac733223 - ssdeep:
768:qgGzpDfAMwjd22ScPb2/d3RTru3QD5z4VIoQmGTc4qj9dshNc80h0uS0L090ZQa:3GFTATa/RxGQ9MVIolGTc4qfsfc8KJSa - TLSH:
T1E232CEF714ABDC4DBD8A6707B9A70154601AC68C7232A2B068C83B6DD87C6FCAD104B1 - Submitted as: 59344786927.pdf
- File type: pdf · Size: 45266 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/f9e0e2cc-40c9-4939-b328-0d4a9de1c952/nodajemagudaleb.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=financial+forecasting+planning+and+budgeting+pdf, https://uploads.strikinglycdn.com/files/f9e0e2cc-40c9-4939-b328-0d4a9de1c952/nodajemagudaleb.pdf, https://uploads.strikinglycdn.com/files/b3dad093-bc48-4780-be46-7dd277c5885a/govugudapaxadegerulefi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=financial+forecasting+planning+and+budgeting+pdf
- https://uploads.strikinglycdn.com/files/f9e0e2cc-40c9-4939-b328-0d4a9de1c952/nodajemagudaleb.pdf
- https://uploads.strikinglycdn.com/files/b3dad093-bc48-4780-be46-7dd277c5885a/govugudapaxadegerulefi.pdf
- https://uploads.strikinglycdn.com/files/a9d7a327-44c8-41fd-ab11-c7af3cc580dd/najobipilemawidiponaxiru.pdf
- https://site-1040132.mozfiles.com/files/1040132/63412572095.pdf
- https://site-1039777.mozfiles.com/files/1039777/50541979982.pdf
- https://site-1036923.mozfiles.com/files/1036923/noxujokajev.pdf
- https://site-1036691.mozfiles.com/files/1036691/23901268715.pdf
- https://cdn.shopify.com/s/files/1/0463/0321/5778/files/earth_science_word_search_answers.pdf
- https://cdn.shopify.com/s/files/1/0481/0352/2467/files/64112684920.pdf
- https://cdn.shopify.com/s/files/1/0465/1014/5694/files/kusoporow.pdf
- https://cdn.shopify.com/s/files/1/0492/0370/8053/files/sandor_katz_wild_fermentation.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1040132.mozfiles.com
- site-1039777.mozfiles.com
- site-1036923.mozfiles.com
- site-1036691.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report