SUSPICIOUS — 61220907164.pdf
SUSPICIOUS — 61220907164.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
cb30ffeee5842a5158dd23a15777e60379113ae5af8b1a3ece88a73262a6f83c - SHA-1:
2e171cbb7d11190d57b444102ff4a258dc3f1067 - MD5:
abb76bb1dff1c2e6c264e27e038e2557 - ssdeep:
768:rgGzpDIYfz7jH55sZ611ipQbyDyUFagjYJZqCM5A1rhzjot8uowM4X:UGFcM/LvioyD8xJZqDIh3o/owM4X - TLSH:
T18631AEF340ABED8C7A86AB039CFB10851089D34CB17397705598BB6CD5BC6BDAE11960 - Submitted as: 61220907164.pdf
- File type: pdf · Size: 41783 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://files.randysnfldcountrymusic.com/uploads/1/3/1/4/131437246/xupefes.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=fl+12+crack, https://uploads.strikinglycdn.com/files/e49cce08-a8c3-4bdd-a831-fa0f830c9d07/62925606315.pdf, https://uploads.strikinglycdn.com/files/9e0573cb-cc41-431b-97aa-c7fccb1da8a2/weruxavavunisekis.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=fl+12+crack
- https://uploads.strikinglycdn.com/files/e49cce08-a8c3-4bdd-a831-fa0f830c9d07/62925606315.pdf
- https://uploads.strikinglycdn.com/files/9e0573cb-cc41-431b-97aa-c7fccb1da8a2/weruxavavunisekis.pdf
- https://uploads.strikinglycdn.com/files/0d1292b6-928d-40b0-af21-0bd0d468e250/fodotelibi.pdf
- https://uploads.strikinglycdn.com/files/5d3f895f-6c8c-4150-b1da-f573b5c76fa1/9938427030.pdf
- https://uploads.strikinglycdn.com/files/85935369-f4bb-479f-9aef-b0c5f6e47ab5/18711635901.pdf
- http://files.randysnfldcountrymusic.com/uploads/1/3/1/4/131437246/xupefes.pdf
- http://files.rooznote.com/uploads/1/3/0/9/130969681/2143b.pdf
- http://jolekazap.followtheleaderedu.com/uploads/1/3/0/8/130874277/a4519aba31eb1ac.pdf
- http://puwabuju.cruzah.com/uploads/1/3/0/7/130775565/4dbe99db2f54c9d.pdf
- http://tojoz.stlinuslions.com/uploads/1/3/0/7/130776644/7374301.pdf
- https://site-1037870.mozfiles.com/files/1037870/87023271268.pdf
- https://site-1038317.mozfiles.com/files/1038317/28933193709.pdf
- https://site-1036767.mozfiles.com/files/1036767/5329099822.pdf
- https://site-1037881.mozfiles.com/files/1037881/tilesujodujetugegegupov.pdf
- https://uploads.strikinglycdn.com/files/39297d4e-c80f-4df8-ac8b-3a4ce715d9b3/luputedeterexut.pdf
- https://uploads.strikinglycdn.com/files/c4496fb2-896e-4991-88ab-a601d3994eca/tipuzisasuwerububitirej.pdf
- https://uploads.strikinglycdn.com/files/94d67a4c-e9ba-444a-ade0-f086a070213b/suzanivodoved.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- files.randysnfldcountrymusic.com
- files.rooznote.com
- jolekazap.followtheleaderedu.com
- puwabuju.cruzah.com
- tojoz.stlinuslions.com
- site-1037870.mozfiles.com
- site-1038317.mozfiles.com
- site-1036767.mozfiles.com
- site-1037881.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report