SUSPICIOUS — 87972569954.pdf
SUSPICIOUS — 87972569954.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
dd062a8e23f22d0e47f53a8376f0e6665a30e77441d1e30328bebac60187ee0c - SHA-1:
738f2efedac82b4d4b548cc2c3aff0ead03dbcb6 - MD5:
d5417d7a79f80cd9588ca8cb68fe39b6 - ssdeep:
1536:EGFgebzh/WSLMcJ4SBvIo1HmHW9mlgB7:RFgebsSwG4SBH1Hmm8K - TLSH:
T1D9339EF340A7DD8C7AC69F037ABA245C6549DB4D2132A7949488776CC8BC27C6F60E60 - Submitted as: 87972569954.pdf
- File type: pdf · Size: 51353 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/3d42f054-29d5-4a3f-9f61-c7ecde4d1afe/nobikeribebaxufije.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=the+art+of+scientific+storytelling+pdf, https://uploads.strikinglycdn.com/files/3d42f054-29d5-4a3f-9f61-c7ecde4d1afe/nobikeribebaxufije.pdf, https://uploads.strikinglycdn.com/files/13d055b4-017c-41e5-9781-1ed59d615fc0/xafetolomubixajoxoleluruf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=the+art+of+scientific+storytelling+pdf
- https://uploads.strikinglycdn.com/files/3d42f054-29d5-4a3f-9f61-c7ecde4d1afe/nobikeribebaxufije.pdf
- https://uploads.strikinglycdn.com/files/13d055b4-017c-41e5-9781-1ed59d615fc0/xafetolomubixajoxoleluruf.pdf
- https://uploads.strikinglycdn.com/files/61eeb481-4fb2-4ab2-a10b-2f08b4ea0910/35292335685.pdf
- https://cdn-cms.f-static.net/uploads/4366362/normal_5f8dbba4f2eeb.pdf
- https://cdn-cms.f-static.net/uploads/4388282/normal_5f8d4360c0f24.pdf
- https://cdn-cms.f-static.net/uploads/4369656/normal_5f89fdeb77b1f.pdf
- https://cdn-cms.f-static.net/uploads/4366406/normal_5f871b054788d.pdf
- https://miremewokar.weebly.com/uploads/1/3/0/7/130738658/muzaduzaram-tulofawo.pdf
- https://tugajepefur.weebly.com/uploads/1/3/1/4/131453805/110597.pdf
- https://cdn-cms.f-static.net/uploads/4371814/normal_5f8d431b551f3.pdf
- https://cdn-cms.f-static.net/uploads/4387813/normal_5f8ec4638e7af.pdf
- https://cdn-cms.f-static.net/uploads/4386622/normal_5f911c39d4c41.pdf
- https://cdn-cms.f-static.net/uploads/4369629/normal_5f8be74022301.pdf
- https://s3.amazonaws.com/henghuili-files2/49038290441.pdf
- https://s3.amazonaws.com/tizowodifi/corporations_act_2001_cth.pdf
- https://s3.amazonaws.com/mibiwivanetuj/army_apft_score_chart_walk.pdf
- https://s3.amazonaws.com/henghuili-files/zokulilaxuwum.pdf
- https://s3.amazonaws.com/fekaduvopigab/7th_grade_math_benchmark_test.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- miremewokar.weebly.com
- tugajepefur.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report