SUSPICIOUS — 58072821627.pdf
SUSPICIOUS — 58072821627.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b68581c1565266f485adfd42fd8edf3beed954124f081c1a4167806a521f4927 - SHA-1:
6de57847fd7deb74b36e0346ac26332e686471b6 - MD5:
84b45f51d986ca869417a77f6720c141 - ssdeep:
768:JIgGzpDrdaLsV0cj5hbLQwy2Xu7pxeNeM1rlIUZQs+uFtPWYL1fyGKj0R:JFGFnhQwyD93qrlIcQs+uFsYYGKj0R - TLSH:
T1E4319DF71097EC8D36869B136DEA11A96046C78D7237BB60089C7B7CE87C5BD2E50821 - Submitted as: 58072821627.pdf
- File type: pdf · Size: 41924 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://files.ttc1976.com/uploads/1/3/0/9/130969297/27856c5.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=be+crushed+by+a+speeding+wall, http://files.ttc1976.com/uploads/1/3/0/9/130969297/27856c5.pdf, http://gufifik.cutonemath.com/uploads/1/3/1/1/131164250/pozos-ledogefu-goduxev.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=be+crushed+by+a+speeding+wall
- http://files.ttc1976.com/uploads/1/3/0/9/130969297/27856c5.pdf
- http://gufifik.cutonemath.com/uploads/1/3/1/1/131164250/pozos-ledogefu-goduxev.pdf
- http://bavuli.personalpilatesma.com/uploads/1/3/0/7/130739235/d91eb7bf6b.pdf
- http://files.bestbrushforward.com/uploads/1/3/2/8/132816087/genesulakavon-kosujanologul-puwakeded-vixorovavur.pdf
- https://cdn.shopify.com/s/files/1/0435/8258/7039/files/autoenginuity_scan_tool.pdf
- https://cdn.shopify.com/s/files/1/0488/2730/2053/files/tema_para_iphone_8_emoji_keyboard_apk.pdf
- https://cdn.shopify.com/s/files/1/0437/9725/0205/files/publicly_vs_publically_ap_style.pdf
- https://cdn.shopify.com/s/files/1/0481/6646/9781/files/guide_rod_laser_mp.pdf
- https://cdn.shopify.com/s/files/1/0439/3094/3643/files/romeo_and_juliet_webquest_answer_key.pdf
- https://uploads.strikinglycdn.com/files/7e77a5d2-edb1-4c2a-b824-2f204ce52c81/17781974710.pdf
- https://uploads.strikinglycdn.com/files/c1611867-b163-4e5f-b4d0-771007357074/sufil.pdf
- https://cdn.shopify.com/s/files/1/0431/5840/5276/files/photosynthesis_crossword_puzzle_answer_key_science_teachers.pdf
- https://cdn.shopify.com/s/files/1/0431/4329/9234/files/soxegitaditibuzakidiz.pdf
- https://cdn.shopify.com/s/files/1/0430/5597/2506/files/3944489876.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- files.ttc1976.com
- gufifik.cutonemath.com
- bavuli.personalpilatesma.com
- files.bestbrushforward.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report