SUSPICIOUS — 71686011745.pdf
SUSPICIOUS — 71686011745.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
cdf0b953b3a9e85afea58e08b144aa21dd008c107e5585aad8845898b3eb39a5 - SHA-1:
f319e0a8695c36420be2ac47aa52b2dfca84b790 - MD5:
b5482f745525e2d612f3325b4068e188 - ssdeep:
768:ygGzpD92owxHdK+gLBQcX+nNh5MJZbkYlQlIrKFSNuNCgSm3h8i:vGF5EFn2QcuNAJxkYlg5FNNR3h8i - TLSH:
T162329EF361A7EC8C7687AB439DAA1499908AD7887133977044D97B2CC4783FE2F00961 - Submitted as: 71686011745.pdf
- File type: pdf · Size: 45526 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://files.trubodyphysicaltherapy.com/uploads/1/3/2/8/132814194/gegaxilabaguz-japopifarok-mufewekanezukuf-dolamitosixenor.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=gordon+ramsay+ultimate+cookery+cours, http://files.alexandrarichards.net/uploads/1/3/0/7/130776898/parore.pdf, http://zefowati.nowasteballarat.org.au/uploads/1/3/0/7/130776716/43825a0.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=gordon+ramsay+ultimate+cookery+cours
- http://files.alexandrarichards.net/uploads/1/3/0/7/130776898/parore.pdf
- http://zefowati.nowasteballarat.org.au/uploads/1/3/0/7/130776716/43825a0.pdf
- http://files.jleaton.com/uploads/1/3/0/7/130739004/9700349.pdf
- http://nixem.windowviper.com/uploads/1/3/0/8/130874413/xuvuvi.pdf
- http://files.trubodyphysicaltherapy.com/uploads/1/3/2/8/132814194/gegaxilabaguz-japopifarok-mufewekanezukuf-dolamitosixenor.pdf
- http://files.goodshepherdschoolgss.com/uploads/1/3/2/6/132695455/pesenaxa.pdf
- http://gabafip.intergenerationalchange.org/uploads/1/3/1/4/131437693/c592ca5.pdf
- http://jirofa.cleanestwindowscolorado.com/uploads/1/3/1/8/131856331/bisuk.pdf
- http://xupujelut.manuelademedeiros.com/uploads/1/3/0/7/130776485/fadukarikode.pdf
- http://files.modernliving.website/uploads/1/3/2/8/132816042/2920520.pdf
- http://files.enloearts.org/uploads/1/3/2/6/132695302/3461598.pdf
- http://files.12southcarriagehouse.com/uploads/1/3/2/7/132710665/c76f3db.pdf
- http://kuruxuwi.matthew-jarvis.co.uk/uploads/1/3/1/8/131871825/witelizerabuv.pdf
- https://uploads.strikinglycdn.com/files/4ed31ae0-0fd2-4b47-82b6-71b66740a261/92557103230.pdf
- https://uploads.strikinglycdn.com/files/f96db643-a3d6-44c8-aa8c-e0af89f05609/zexubogoluwijulibotivisa.pdf
- https://uploads.strikinglycdn.com/files/e98476e3-e48f-49ea-984c-abd75ed0b1c2/jetafojotabamipuziked.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- files.alexandrarichards.net
- zefowati.nowasteballarat.org.au
- files.jleaton.com
- nixem.windowviper.com
- files.trubodyphysicaltherapy.com
- files.goodshepherdschoolgss.com
- gabafip.intergenerationalchange.org
- jirofa.cleanestwindowscolorado.com
- xupujelut.manuelademedeiros.com
- files.enloearts.org
- files.12southcarriagehouse.com
- kuruxuwi.matthew-jarvis.co.uk
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
- files.modernliving.website
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report