SUSPICIOUS — 64561913579.pdf
SUSPICIOUS — 64561913579.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bfe73b5408d5716764df5c3048d3639c8f38f284ce984875ed522b90d6cb05bd - SHA-1:
bbc48064aec80e4a7737911ee7e413cefc4a9243 - MD5:
e841f169200a2ac722783079bbfb42c9 - ssdeep:
768:egGzpDAslBN0VHiBIAK3MDyg4tTj95AwZZm+2sObnIQzKv6esq9Y3fxM+sck1f:bGFcsv/4tHc+sbIQ+Sesq9GNFk1f - TLSH:
T18C33BFF32597EC8C79866F43A9BA11651148C64D3237E770985CBB3ED0B86BD6E009A0 - Submitted as: 64561913579.pdf
- File type: pdf · Size: 49620 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/c193118b-a5f5-48fd-b37e-092cf9081526/15695921067.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=electronic+document+management+system+pdf, https://cdn.shopify.com/s/files/1/0440/7282/9078/files/iqiyi_earnings_report.pdf, https://cdn.shopify.com/s/files/1/0432/5831/4912/files/vscode_install_omnisharp_manually.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=electronic+document+management+system+pdf
- https://cdn.shopify.com/s/files/1/0440/7282/9078/files/iqiyi_earnings_report.pdf
- https://cdn.shopify.com/s/files/1/0432/5831/4912/files/vscode_install_omnisharp_manually.pdf
- https://cdn.shopify.com/s/files/1/0437/5294/7873/files/robotics_competition_2020_chicago.pdf
- https://cdn.shopify.com/s/files/1/0433/0697/5382/files/gegokozik.pdf
- https://cdn.shopify.com/s/files/1/0433/9276/2006/files/apk_on_pc_download.pdf
- https://uploads.strikinglycdn.com/files/dd52ab8e-b14f-4a6c-aaec-dd9be9082fe1/lozagizozade.pdf
- https://uploads.strikinglycdn.com/files/ba8cb63f-8938-4a40-b041-1e528f87860b/78615160077.pdf
- https://uploads.strikinglycdn.com/files/c193118b-a5f5-48fd-b37e-092cf9081526/15695921067.pdf
- https://uploads.strikinglycdn.com/files/82d5bc9a-dfec-4b88-bb7e-733b1d0f5e9c/99042956039.pdf
- https://uploads.strikinglycdn.com/files/4a6f7bc0-2f3e-45ae-a73d-444d34a3d9fa/73281212505.pdf
- https://uploads.strikinglycdn.com/files/da467ad7-8e25-4a94-8535-f4190f1a30f5/figuwagi.pdf
- https://uploads.strikinglycdn.com/files/ddf6bd00-bfbe-4cf1-986b-0ea802036745/namimexapono.pdf
- https://uploads.strikinglycdn.com/files/2450df09-480e-4e5b-bb10-f8e98533ecc2/23184541887.pdf
- https://uploads.strikinglycdn.com/files/710f3d78-e69e-45ce-93b9-dd2e3726eb5e/29313580403.pdf
- https://uploads.strikinglycdn.com/files/3ab66ca8-598a-465d-a1ca-9124dd314296/32536327983.pdf
- https://uploads.strikinglycdn.com/files/76d1b2cb-7228-4c49-a871-e4a36fafaf66/birisatinujulad.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report