SUSPICIOUS — 70148861485.pdf
SUSPICIOUS — 70148861485.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
cf99179dab8c58b5d67a6db7674d985233f70273ee1df27061d55d4cf28bb827 - SHA-1:
c0c344d4c37b259fbffbbc7f7ad452710d758fb9 - MD5:
f40dc1a1ad2c0a9034758d32bc714d1c - ssdeep:
768:cgGzpDkA3WAkVZN8SwtaHd2XLGD0Zk4C0Lr1eJYT/DloRinHDGE05ZCVWKHMUv:5GFguzXLlk4IyrJHiFZg1HMUv - TLSH:
T14332BEF74097EDCC768BAB1399FB0119A546D6897132AAA4448C732CC47C6FD7F40A60 - Submitted as: 70148861485.pdf
- File type: pdf · Size: 46594 bytes
- Verdict: suspicious (58/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://zelopifal.mdexpertsllc.com/uploads/1/3/0/9/130969054/55a170f9ad.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=schroeder+thermal+physics, http://files.palmettomdpa.net/uploads/1/3/0/7/130740571/1742123.pdf, http://zelopifal.mdexpertsllc.com/uploads/1/3/0/9/130969054/55a170f9ad.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=schroeder+thermal+physics
- http://files.palmettomdpa.net/uploads/1/3/0/7/130740571/1742123.pdf
- http://zelopifal.mdexpertsllc.com/uploads/1/3/0/9/130969054/55a170f9ad.pdf
- http://files.chenjian-art.com/uploads/1/3/1/3/131381605/2309642.pdf
- https://cdn.shopify.com/s/files/1/0429/6228/8793/files/89002445501.pdf
- https://cdn.shopify.com/s/files/1/0484/9624/6946/files/comparative_bar_chart_questions.pdf
- https://cdn.shopify.com/s/files/1/0434/6229/5714/files/triumph_duo_bike_trailer_review.pdf
- https://cdn.shopify.com/s/files/1/0500/2500/5206/files/zakedunedotadanoziw.pdf
- https://uploads.strikinglycdn.com/files/eb7fa877-372b-4fba-9129-540f0335e150/73612014005.pdf
- https://uploads.strikinglycdn.com/files/85fca48c-5a3d-420e-b291-2499df5bada0/36643491878.pdf
- https://uploads.strikinglycdn.com/files/c3d6a583-42df-4c03-8f6d-8296f57585ef/28600331310.pdf
- https://uploads.strikinglycdn.com/files/8e550558-0f00-4e17-943e-04e7aff276d2/33002342842.pdf
- https://uploads.strikinglycdn.com/files/9ae2f3ca-dd06-49be-8fa3-bcb42a38c0fb/41895080136.pdf
- https://cdn.shopify.com/s/files/1/0266/8789/7787/files/lasanogupagu.pdf
- https://cdn.shopify.com/s/files/1/0435/6558/0437/files/josutajuverosomuzopu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- files.palmettomdpa.net
- zelopifal.mdexpertsllc.com
- files.chenjian-art.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report