SUSPICIOUS — 17918136913.pdf
SUSPICIOUS — 17918136913.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b7ef6840dc2858b90b9934c25339701db7f7b14c5d1e52510af637ecbe19a997 - SHA-1:
7e06fb697d785c9f75f03558446aed794b7bec4a - MD5:
bcbec0193597edeb1cd76fb95c04efc3 - ssdeep:
768:WPgGzpD8ptx8TT0D0qQK2Djyi1A5iGKeLvXpKRqfZpOhl0q6hpuafWkgftjjP:7GFQptxusv0UO/0Hcbf1P - TLSH:
T14B327BF360A3ED0C7ACBAF0369AF2569954DE788A132A7604498772CC47C37D3E10965 - Submitted as: 17918136913.pdf
- File type: pdf · Size: 46921 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/9d8f8a12-2fc0-4ae7-85f5-b47993d3c7e0/pobenolekow.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.cc/pify?keyword=library+facebook+for+android, https://cdn-cms.f-static.net/uploads/4366969/normal_5f8d03b6beee9.pdf, https://cdn-cms.f-static.net/uploads/4376601/normal_5f8abe309e817.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/pify?keyword=library+facebook+for+android
- https://cdn-cms.f-static.net/uploads/4366969/normal_5f8d03b6beee9.pdf
- https://cdn-cms.f-static.net/uploads/4376601/normal_5f8abe309e817.pdf
- https://cdn-cms.f-static.net/uploads/4369168/normal_5f8b008ba5a41.pdf
- https://cdn-cms.f-static.net/uploads/4367903/normal_5f887d570b153.pdf
- https://cdn-cms.f-static.net/uploads/4373987/normal_5f8911a3b8f98.pdf
- https://uploads.strikinglycdn.com/files/9d8f8a12-2fc0-4ae7-85f5-b47993d3c7e0/pobenolekow.pdf
- https://uploads.strikinglycdn.com/files/658e025d-a698-4184-b08a-e6a4168684f7/bike_authorization_letter_format_west_bengal.pdf
- https://uploads.strikinglycdn.com/files/69805d9b-1881-4f5d-a087-094588a7af98/45601726368.pdf
- https://cdn-cms.f-static.net/uploads/4366978/normal_5f8bbd6fcbcd4.pdf
- https://cdn-cms.f-static.net/uploads/4367645/normal_5f887db099e72.pdf
- https://cdn-cms.f-static.net/uploads/4383450/normal_5f8c8c8aa3207.pdf
- https://cdn-cms.f-static.net/uploads/4366313/normal_5f874273968c4.pdf
- https://cdn-cms.f-static.net/uploads/4368501/normal_5f8829ea8fae4.pdf
- https://uploads.strikinglycdn.com/files/f78dea55-f673-46a6-87b2-6738f60ef98f/72456420479.pdf
- https://uploads.strikinglycdn.com/files/a6934078-0aa9-40a5-9966-a12a1b41da2f/vamitegojuxi.pdf
- https://uploads.strikinglycdn.com/files/67cb1157-14f8-4cd2-9646-2deaceb8bbaa/bakolilazikud.pdf
- https://uploads.strikinglycdn.com/files/580c0ebc-2769-4394-8fe9-f2793b72b0e6/31109373135.pdf
- https://uploads.strikinglycdn.com/files/3a0c9f2b-94d1-41f2-9512-12450c40827a/john_deere_roosa_master_injector_pum.pdf
- https://lifagixuwemup.weebly.com/uploads/1/3/0/9/130969738/wubifipexedepug_nirejujos_tolis.pdf
- https://jikolugoxolij.weebly.com/uploads/1/3/1/3/131379047/namedakekedosane.pdf
- https://talapilodegopez.weebly.com/uploads/1/3/0/9/130969507/2171885.pdf
- https://firedisivimi.weebly.com/uploads/1/3/0/9/130969818/zenolari_zumef_pogirixis.pdf
- https://soxajenukaru.weebly.com/uploads/1/3/0/8/130874283/dikotinewo_povaxa_nivuwusonuzeg_dasugiran.pdf
- https://cdn.shopify.com/s/files/1/0481/6093/1991/files/anandamela_pujabarshiki_free_download.pdf
Embedded domains
- ttraff.cc
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- lifagixuwemup.weebly.com
- jikolugoxolij.weebly.com
- talapilodegopez.weebly.com
- firedisivimi.weebly.com
- soxajenukaru.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report