SUSPICIOUS — 53754627873.pdf
SUSPICIOUS — 53754627873.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c00db41793eeffbeca0db69770761382cfc3d9527cc2c048192321721ff0ea18 - SHA-1:
791be536b4df3bf13d718d32b6c28ab1df005874 - MD5:
e0e57d67b4178ab47d53adaa4bb208cf - ssdeep:
768:tgGzpDgpWK71m/6TV180UuaSOrdHGF3O5yC+g:OGF0pWgVG0UnSqHGF3Oqg - TLSH:
T1972F9EF3519BEC8C7A8BDB436DEA2409504AC74C6236D7A44858377ED0BC6BDBE14460 - Submitted as: 53754627873.pdf
- File type: pdf · Size: 35093 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/fb40e599-085f-4f00-a2d5-7db5e259c85f/lesifotemerigi.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=cambridge+igcse+20th+century+history+pdf, https://uploads.strikinglycdn.com/files/fb40e599-085f-4f00-a2d5-7db5e259c85f/lesifotemerigi.pdf, https://uploads.strikinglycdn.com/files/6d743b08-4443-4ad7-93b4-648c5829bca0/mevepajatisubixaruxanitex.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=cambridge+igcse+20th+century+history+pdf
- https://uploads.strikinglycdn.com/files/fb40e599-085f-4f00-a2d5-7db5e259c85f/lesifotemerigi.pdf
- https://uploads.strikinglycdn.com/files/6d743b08-4443-4ad7-93b4-648c5829bca0/mevepajatisubixaruxanitex.pdf
- https://uploads.strikinglycdn.com/files/26628953-56b7-416c-a2a1-0ababf7c919f/61301268453.pdf
- https://uploads.strikinglycdn.com/files/98aee5f5-2327-484e-a434-faf01de036f3/sufulobanopefawijixom.pdf
- https://site-1038840.mozfiles.com/files/1038840/93828876726.pdf
- https://site-1038510.mozfiles.com/files/1038510/2828777656.pdf
- https://site-1041693.mozfiles.com/files/1041693/sikubikativuk.pdf
- https://site-1038360.mozfiles.com/files/1038360/satenowipow.pdf
- https://cdn.shopify.com/s/files/1/0432/9432/6939/files/64320534014.pdf
- https://cdn.shopify.com/s/files/1/0483/9951/5816/files/ufc_mod_apk_rexdl.pdf
- https://cdn.shopify.com/s/files/1/0432/2679/2093/files/dumikaposelijuret.pdf
- https://cdn.shopify.com/s/files/1/0434/1514/2567/files/nozimizusaleka.pdf
- https://site-1042193.mozfiles.com/files/1042193/novubopuwadatefupujexop.pdf
- https://site-1038440.mozfiles.com/files/1038440/voveramapumetunodepu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1038840.mozfiles.com
- site-1038510.mozfiles.com
- site-1041693.mozfiles.com
- site-1038360.mozfiles.com
- cdn.shopify.com
- site-1042193.mozfiles.com
- site-1038440.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report