SUSPICIOUS — 14758064797.pdf
SUSPICIOUS — 14758064797.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c3918b5f8615c845257fc7b0b0c331d98789f4424ad1e538b973b0568a197ec0 - SHA-1:
cef657447ea2c2c3c17a62dc69107db325ca8d27 - MD5:
5f539b2a379b524163d0c83a4fe9c645 - ssdeep:
768:1gGzpDkpjwxsBmLcWPbvZCoAi7xYIzQVTk73PYj6qCKXGf2AA3RyiwCMHwqdNI1a:mGFApjEzBh7qIzQxkjPYj6LKXf5RLMXp - TLSH:
T193329EF35163DC8C7A8FAB1378FA04986406D68C7172CAA0549CB76CD4B86FD6D00AA1 - Submitted as: 14758064797.pdf
- File type: pdf · Size: 45409 bytes
- Verdict: suspicious (58/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/72a765cb-16a6-491c-bed6-b2994e1b96b5/37384956556.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=eternal+darkness+rom+fr, https://cdn.shopify.com/s/files/1/0480/7190/1347/files/natuxegoxof.pdf, https://cdn.shopify.com/s/files/1/0479/5976/9255/files/ghettoization_ap_human_geography.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=eternal+darkness+rom+fr
- https://cdn.shopify.com/s/files/1/0480/7190/1347/files/natuxegoxof.pdf
- https://cdn.shopify.com/s/files/1/0479/5976/9255/files/ghettoization_ap_human_geography.pdf
- https://cdn.shopify.com/s/files/1/0483/6317/6085/files/madison_movie_guide.pdf
- https://cdn.shopify.com/s/files/1/0431/5663/5804/files/bsa_safety_merit_badge_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0438/3562/1536/files/bash_neil_labute_monologue.pdf
- https://uploads.strikinglycdn.com/files/f0b7d954-0d43-4520-a1ba-c18dcab6373a/nuwejidunelijelusujawul.pdf
- https://uploads.strikinglycdn.com/files/72a765cb-16a6-491c-bed6-b2994e1b96b5/37384956556.pdf
- http://files.grindfitnesstn.com/uploads/1/3/0/7/130740199/gasodorizaj_rujikul_vezug.pdf
- http://files.drenzidesigns.com/uploads/1/3/1/4/131453220/4097725.pdf
- http://files.noretasdecor.com/uploads/1/3/1/4/131453902/f352e04c6aaea.pdf
- http://files.ccbsm.org/uploads/1/3/0/8/130873715/zudevorixo-pepezapesetam.pdf
- https://cdn.shopify.com/s/files/1/0497/6007/5930/files/5384293397.pdf
- https://cdn.shopify.com/s/files/1/0435/2924/0727/files/smash_ultimate_classic_unlock_chart.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- files.grindfitnesstn.com
- files.drenzidesigns.com
- files.noretasdecor.com
- files.ccbsm.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report