SUSPICIOUS — 8623912186.pdf
SUSPICIOUS — 8623912186.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b305ca8b1f007a71b158a6b4d3895da6d5f5caed3ee7769320bdc6fee5c4cda7 - SHA-1:
056a648295dd93749b9bae47463cce6ab676dd6d - MD5:
07dcdab0945f995ab30e4720c88b8597 - ssdeep:
768:zgGzpD4QKBH4eYjVmkZHAF8XTDO2/qHgZNTS3xQ6gRE33AJCZKa1jFE:MGFsZSfZgFqTr6/3uCoadFE - TLSH:
T16B32ADF75197ED8CBA969B43ADE701A16146C288A133D2B044C83A6CC4BC5FD7E14D72 - Submitted as: 8623912186.pdf
- File type: pdf · Size: 44572 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/f8cf4884-5a7c-4943-9f0a-2ae6c32f6a3a/74907914466.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=2003+ford+focus+repair+manual+download, https://uploads.strikinglycdn.com/files/f8cf4884-5a7c-4943-9f0a-2ae6c32f6a3a/74907914466.pdf, https://uploads.strikinglycdn.com/files/3e288728-118f-44d5-ad72-9553c99ea804/sizavalani.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=2003+ford+focus+repair+manual+download
- https://uploads.strikinglycdn.com/files/f8cf4884-5a7c-4943-9f0a-2ae6c32f6a3a/74907914466.pdf
- https://uploads.strikinglycdn.com/files/3e288728-118f-44d5-ad72-9553c99ea804/sizavalani.pdf
- https://uploads.strikinglycdn.com/files/42d52962-4598-4f42-ae5e-2a41ca347d59/newosizofavewodixi.pdf
- https://uploads.strikinglycdn.com/files/1e295006-350d-4d0f-bc32-e50dfdd62af2/81526326560.pdf
- https://uploads.strikinglycdn.com/files/6374f158-d233-4d66-8921-0d796e78f0fd/rukamelonas.pdf
- https://uploads.strikinglycdn.com/files/0895ef03-b72f-4363-9ded-55aa1b42e7ac/70681293831.pdf
- https://uploads.strikinglycdn.com/files/fe208d84-fa1e-4d75-b85b-c7727493ec7c/wutikesenevivigu.pdf
- https://uploads.strikinglycdn.com/files/860912aa-cf07-4481-8c86-f414ddc47b64/rinusotuvij.pdf
- https://uploads.strikinglycdn.com/files/d2490ff1-b5e1-4466-ad9c-fd4508fc5f22/78065894414.pdf
- https://uploads.strikinglycdn.com/files/71713e03-4b5d-4a4e-91dd-fbd8c2734a30/7448853645.pdf
- https://cdn.shopify.com/s/files/1/0481/9307/7405/files/google_form_password_hack.pdf
- https://cdn.shopify.com/s/files/1/0433/7578/8188/files/rotim.pdf
- http://davunema.micheleashlee.com/uploads/1/3/2/8/132814975/vatosegizawokutewaw.pdf
- http://xegenikam.cathycarterartist.com/uploads/1/3/0/7/130775565/e747448a7076.pdf
- http://files.issness.com/uploads/1/3/0/7/130739084/tidozarebenekiv-babuve.pdf
- http://tawaketen.truckersunitedforfreedom.com/uploads/1/3/2/7/132710795/tewitazo_nemurexosebipe_buwurenewogezu_majetiporitaz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- davunema.micheleashlee.com
- xegenikam.cathycarterartist.com
- files.issness.com
- tawaketen.truckersunitedforfreedom.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report