SUSPICIOUS — 47644765695.pdf
SUSPICIOUS — 47644765695.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d0a222287da244c9d39be1c7ba43e0ac23fa4149ece1a813ff0db03df3425245 - SHA-1:
323814a51814f36303218ff45d2ce7a46c3c5c62 - MD5:
128a55c39181349c9074c62ac0d919d9 - ssdeep:
768:7gGzpD2w7dcck/jAeyGpeBtSQZR5958r7BsF3MNYyU75PunlCXsGPCGSx0yFx:EGFi2dojA/GpaUpbNYb5WlisGFSx0yFx - TLSH:
T16332AEF314A7DD885A8AA723AAE600456149DB8D3137877408DC7B7CC4BC2BEAF50D61 - Submitted as: 47644765695.pdf
- File type: pdf · Size: 46775 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/3a1d2653-13d3-4956-bbd4-bf2132e3fb81/pezilifoniridi.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=acknowledgement+sample+for+project+report+pdf, https://uploads.strikinglycdn.com/files/3a1d2653-13d3-4956-bbd4-bf2132e3fb81/pezilifoniridi.pdf, https://uploads.strikinglycdn.com/files/10a53376-31e4-4150-a3f6-469a91039f3e/zegapepubire.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=acknowledgement+sample+for+project+report+pdf
- https://uploads.strikinglycdn.com/files/3a1d2653-13d3-4956-bbd4-bf2132e3fb81/pezilifoniridi.pdf
- https://uploads.strikinglycdn.com/files/10a53376-31e4-4150-a3f6-469a91039f3e/zegapepubire.pdf
- https://uploads.strikinglycdn.com/files/8c0dfbef-5a9a-4aae-ad22-3ba8851ff591/42074825839.pdf
- https://cdn.shopify.com/s/files/1/0432/1309/5073/files/ginalububerise.pdf
- https://cdn.shopify.com/s/files/1/0429/3571/3958/files/92099330149.pdf
- https://cdn.shopify.com/s/files/1/0432/3681/9104/files/446416640.pdf
- https://cdn.shopify.com/s/files/1/0430/4932/0610/files/zosux.pdf
- https://site-1037885.mozfiles.com/files/1037885/wunulu.pdf
- https://site-1036632.mozfiles.com/files/1036632/weroromekizebe.pdf
- https://cdn.shopify.com/s/files/1/0457/7371/7670/files/test_for_aldehydes_chemguide.pdf
- https://cdn.shopify.com/s/files/1/0429/8843/7655/files/bug_b_gon_eco_concentrate.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1037885.mozfiles.com
- site-1036632.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report