SUSPICIOUS — 41083838931.pdf
SUSPICIOUS — 41083838931.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b6e5186f6b36e95dff9b8426ebc03b17bfc43d12aaed577042fcf35c304644f9 - SHA-1:
21dcec3c7cabd2eaac09661804dc53e3e96b61c4 - MD5:
dd9389a5d8e025d3bb5e89489379a74c - ssdeep:
768:tgGzpDQjktUngm7tjilhvvTg1Vt4wewHzQVVzLkc/vD1i:OGFCkctmvTg1VDewH8VVpvD1i - TLSH:
T1AB329EF360EBDD4DBA87AF035DFA25A8904AD2496072A374059C6B2CC4BC77D6E40E50 - Submitted as: 41083838931.pdf
- File type: pdf · Size: 44743 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/3891592b-9d39-45b5-8487-34fc5aa4d36f/905126792.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=job+application+letter+for+accountant+assistant+pdf, https://uploads.strikinglycdn.com/files/04987bf0-f553-4cdb-a95a-41611d039eba/kaxopuguwejusibagawipe.pdf, https://uploads.strikinglycdn.com/files/da467ad7-8e25-4a94-8535-f4190f1a30f5/figuwagi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=job+application+letter+for+accountant+assistant+pdf
- https://uploads.strikinglycdn.com/files/04987bf0-f553-4cdb-a95a-41611d039eba/kaxopuguwejusibagawipe.pdf
- https://uploads.strikinglycdn.com/files/da467ad7-8e25-4a94-8535-f4190f1a30f5/figuwagi.pdf
- https://uploads.strikinglycdn.com/files/44394aa8-ad3e-41ef-b1cb-15f5ca8b4346/begivuver.pdf
- https://uploads.strikinglycdn.com/files/5d68f93f-2f48-4c26-b9bc-9747535bd6cc/65922868561.pdf
- https://uploads.strikinglycdn.com/files/619275ad-4717-41b9-8609-175f999dcae9/97611445582.pdf
- https://uploads.strikinglycdn.com/files/3891592b-9d39-45b5-8487-34fc5aa4d36f/905126792.pdf
- https://uploads.strikinglycdn.com/files/f9dff0bd-1ccd-48d9-81b2-321883271f45/15637137791.pdf
- https://uploads.strikinglycdn.com/files/321cb757-e058-47d1-ad44-a159695426bc/mofotukuzugemonif.pdf
- https://uploads.strikinglycdn.com/files/6d105df7-acde-476a-a7fe-f895c2607432/21560249420.pdf
- https://cdn.shopify.com/s/files/1/0438/3899/6642/files/tewapajid.pdf
- https://cdn.shopify.com/s/files/1/0436/2413/6864/files/kirufoxopaborobagigupuw.pdf
- https://cdn.shopify.com/s/files/1/0434/4968/0032/files/28278391488.pdf
- https://uploads.strikinglycdn.com/files/68cc5aa3-46ce-4aae-ab5a-52e7cca83bb2/18174313412.pdf
- https://uploads.strikinglycdn.com/files/b583f2b9-bf8c-484a-8527-97a08b8e6b3a/ferudimafuserunomilitas.pdf
- https://uploads.strikinglycdn.com/files/d71eabcf-7d14-46fb-bf7a-3beedccd4c34/rokisizis.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report