SUSPICIOUS — 58957682969.pdf
SUSPICIOUS — 58957682969.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c61b9c32d2009a6dc1e45939ccde25488f0a313bd9044c534a39d3480eca6423 - SHA-1:
d3360cf8c5eef397e23815bbdb6410ec2b3a9862 - MD5:
242fdbbd5afe3d27517f0df7e88778ca - ssdeep:
1536:TGFgelA4CMAIVXcdE3AvhZTA0SqGt1kM:iFgeljCMnwvhZE0SqGtt - TLSH:
T13135BFF34593ED8C79C7DB836EA721556145C6082232E790048CB77DD9B82BDBF20A61 - Submitted as: 58957682969.pdf
- File type: pdf · Size: 58322 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/42cf10f1-35b4-4583-b0bc-35b647c9c2a1/4266350295.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=la+ph%25C3%25A9nom%25C3%25A9nologie+pour+les+nuls, https://cdn.shopify.com/s/files/1/0496/6304/9879/files/the_lesson_by_toni_cade_bambara_short_summary.pdf, https://cdn.shopify.com/s/files/1/0438/4191/2997/files/pathfinder_kingmaker_draconic_sorcerer_build.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=la+ph%25C3%25A9nom%25C3%25A9nologie+pour+les+nuls
- https://cdn.shopify.com/s/files/1/0496/6304/9879/files/the_lesson_by_toni_cade_bambara_short_summary.pdf
- https://cdn.shopify.com/s/files/1/0438/4191/2997/files/pathfinder_kingmaker_draconic_sorcerer_build.pdf
- https://cdn.shopify.com/s/files/1/0464/6656/4254/files/27501474302.pdf
- https://cdn.shopify.com/s/files/1/0429/2411/4076/files/verizon_lg_cell_phone_manual.pdf
- https://uploads.strikinglycdn.com/files/768db4dc-fc53-4ad0-9f8f-3ab9eda06e8d/52493453079.pdf
- https://uploads.strikinglycdn.com/files/4d15a620-4786-4132-a208-99ce5e5175cb/62983264297.pdf
- https://uploads.strikinglycdn.com/files/084f61b7-b4cf-43e6-bb8d-bf0850608a19/61688315971.pdf
- https://uploads.strikinglycdn.com/files/cf3008df-d0f9-46ad-831e-b768c06c6069/93571779108.pdf
- https://cdn.shopify.com/s/files/1/0428/1437/4054/files/minecraft_kill_all_entities_of_type.pdf
- https://cdn.shopify.com/s/files/1/0479/3152/3239/files/rigenorakulunimeliteduf.pdf
- https://cdn.shopify.com/s/files/1/0482/2410/8696/files/rofewuginituvalo.pdf
- https://uploads.strikinglycdn.com/files/ce49aaee-345f-41ad-8fa4-6aaba3e9a8b1/siwunasufa.pdf
- https://uploads.strikinglycdn.com/files/463587c3-659a-447e-9805-0a8194258b9d/13724975495.pdf
- https://uploads.strikinglycdn.com/files/53432ba5-8e5f-41c2-ab35-31bbc3ab0c4f/dedawirutixaxafu.pdf
- https://uploads.strikinglycdn.com/files/42cf10f1-35b4-4583-b0bc-35b647c9c2a1/4266350295.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- i:\rE3
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report