SUSPICIOUS — 13532643742.pdf
SUSPICIOUS — 13532643742.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d7145d8b46c42ae2d912e2301c67a613d7e4a6c4fb4d8ac29faa0c1bdae2dde5 - SHA-1:
e665b95ac30227df82f118000ebcdd23cbd01395 - MD5:
3613436b64752ea797202826ed19d458 - ssdeep:
768:6gGzpDmpa86LIcAIVcijWPdPIXTFgVisyJIdcj6POtf3ZeZIQi:nGFSpL1QtsyOqj9f3ZeZIQi - TLSH:
T17731AEF31067ED4C6A879B836DB61859618AC68D7232E77019D8779CC5BC2BCBF00920 - Submitted as: 13532643742.pdf
- File type: pdf · Size: 42695 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://gofudi.hhhschoirs.com/uploads/1/3/0/8/130874600/42c159.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=internetsiz+radyo+dinleme+program%25C4%25B1, http://files.puzzlesandbraingames.com/uploads/1/3/1/4/131407152/b4af828ce86a9.pdf, http://gofudi.hhhschoirs.com/uploads/1/3/0/8/130874600/42c159.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=internetsiz+radyo+dinleme+program%25C4%25B1
- http://files.puzzlesandbraingames.com/uploads/1/3/1/4/131407152/b4af828ce86a9.pdf
- http://gofudi.hhhschoirs.com/uploads/1/3/0/8/130874600/42c159.pdf
- http://vufizewa.americanlandscapingservice.com/uploads/1/3/0/7/130776031/da5930702bb2.pdf
- https://cdn.shopify.com/s/files/1/0463/2166/4160/files/lectura_del_cafe_arabe_quito.pdf
- https://cdn.shopify.com/s/files/1/0434/4260/2140/files/gawamasi.pdf
- https://cdn.shopify.com/s/files/1/0496/4142/3012/files/amy_irving_movies_and_tv_shows.pdf
- https://cdn.shopify.com/s/files/1/0483/6317/6085/files/gitazoxa.pdf
- https://cdn.shopify.com/s/files/1/0482/0785/5773/files/zaribizasewofunarog.pdf
- https://cdn.shopify.com/s/files/1/0497/5178/5625/files/dudiwogugafiw.pdf
- https://cdn.shopify.com/s/files/1/0432/0821/2638/files/85018865296.pdf
- https://cdn.shopify.com/s/files/1/0434/3057/6295/files/mifesubomafusu.pdf
- https://cdn.shopify.com/s/files/1/0431/8124/4573/files/33952426583.pdf
- http://gijewowi.kazmetixartistry.com/uploads/1/3/1/8/131856708/7069361.pdf
- http://files.montgomery-jones.com/uploads/1/3/1/8/131856394/ed6c53e9c64682.pdf
- http://sikoruf.smithsoundmusic.com/uploads/1/3/1/3/131398091/c89e6bac9b.pdf
- http://desez.bergmanlandscaping.net/uploads/1/3/2/8/132814930/6d3ee.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- files.puzzlesandbraingames.com
- gofudi.hhhschoirs.com
- vufizewa.americanlandscapingservice.com
- cdn.shopify.com
- gijewowi.kazmetixartistry.com
- files.montgomery-jones.com
- sikoruf.smithsoundmusic.com
- desez.bergmanlandscaping.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report