SUSPICIOUS — 56806503236.pdf
SUSPICIOUS — 56806503236.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
dcd0e9d743091786f79f4d127c051a2c5e3154e31c0df458d92661b9e9a3445c - SHA-1:
6d24427a2e978217e85fa1cb9904355ddb2345cc - MD5:
624b9d3add3dd2c30a482b1b7fa332e4 - ssdeep:
768:+gGzpDW1gwMgcym5AkMbRs2f/KJtMEesEr9QpjnI/ms4tij5Xl4L:7GFKXncy/kefqhesEBOIjQidXCL - TLSH:
T11332BFF32097EEDC2AC77F476DA749897286D2487122E25004DC7B6CC4786ECAF12961 - Submitted as: 56806503236.pdf
- File type: pdf · Size: 46287 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://files.drbryanmills.com/uploads/1/3/0/7/130775504/d4f5e48b28e3c.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=citer+une+utilisation+de+l%2527indigo+synth%25C3%25A9tique, http://files.melbournespeakerhire.com.au/uploads/1/3/1/3/131381450/2350642.pdf, http://files.theoaksathobesound.com/uploads/1/3/1/6/131607023/7119868.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=citer+une+utilisation+de+l%2527indigo+synth%25C3%25A9tique
- http://files.melbournespeakerhire.com.au/uploads/1/3/1/3/131381450/2350642.pdf
- http://files.theoaksathobesound.com/uploads/1/3/1/6/131607023/7119868.pdf
- http://files.daniellerobidoux.com/uploads/1/3/0/8/130874324/ac5cd533.pdf
- http://files.dalesdesignsonzazzle.com/uploads/1/3/0/9/130969758/ramofez-bamudetowi.pdf
- http://files.islandercars.com/uploads/1/3/1/6/131606268/8928382.pdf
- http://fizuba.kathysdanceacademy.com/uploads/1/3/1/4/131437930/fojamariguwuka_linuz_nisew.pdf
- http://bafamanaf.whiskeycreekcondo.com/uploads/1/3/0/7/130739996/5039126.pdf
- http://nilawit.ptbomassage.com/uploads/1/3/1/4/131452929/puwepejaladuro-koxod-wapabi.pdf
- http://files.drbryanmills.com/uploads/1/3/0/7/130775504/d4f5e48b28e3c.pdf
- https://uploads.strikinglycdn.com/files/115365a8-28ae-4069-8d4a-e6f5ef3d3a06/86643795449.pdf
- https://uploads.strikinglycdn.com/files/03b1b022-dbaa-4a82-9591-e3a7dd5365fd/13094705608.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- files.melbournespeakerhire.com.au
- files.theoaksathobesound.com
- files.daniellerobidoux.com
- files.dalesdesignsonzazzle.com
- files.islandercars.com
- fizuba.kathysdanceacademy.com
- bafamanaf.whiskeycreekcondo.com
- nilawit.ptbomassage.com
- files.drbryanmills.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report