SUSPICIOUS — 71540145070.pdf
SUSPICIOUS — 71540145070.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
de931fcc1b559fb36d6df1bf5e8653400e771375be58a00f9dfa016c3abed9ad - SHA-1:
8385c03e2d2ba6c8f31364c502d847d40fb67652 - MD5:
b71fc50eb9ac03da3c0ab29b9de5935c - ssdeep:
1536:3GFtrQvKIWHJmSLmhVglVUJFN2R+zPf8:WFtrY36IFN2Rz - TLSH:
T1DC33C0F394A7FC8C3A8B5753ADF614222085C78C7137A66454E9BA2DC4BC1FCAE40562 - Submitted as: 71540145070.pdf
- File type: pdf · Size: 50155 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://files.mnmsprinkler.com/uploads/1/3/1/8/131856318/fa439.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=mamluks+eu4+guide, https://site-1036880.mozfiles.com/files/1036880/ribedok.pdf, https://site-1038317.mozfiles.com/files/1038317/pakamasivirubataf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=mamluks+eu4+guide
- https://site-1036880.mozfiles.com/files/1036880/ribedok.pdf
- https://site-1038317.mozfiles.com/files/1038317/pakamasivirubataf.pdf
- https://site-1039689.mozfiles.com/files/1039689/14170941477.pdf
- https://site-1037057.mozfiles.com/files/1037057/88096815818.pdf
- https://cdn.shopify.com/s/files/1/0435/2868/3672/files/the_feud_quest_guide.pdf
- https://cdn.shopify.com/s/files/1/0500/2651/2544/files/mass_effect_annihilation_field.pdf
- http://files.wisemountainyoga.com/uploads/1/3/1/3/131397942/7a11f.pdf
- http://files.villatesoristjohn.com/uploads/1/3/1/0/131070151/8161770.pdf
- http://files.differentstrokes-painting.com/uploads/1/3/2/8/132815008/runejuxeg.pdf
- http://files.mnmsprinkler.com/uploads/1/3/1/8/131856318/fa439.pdf
- https://cdn.shopify.com/s/files/1/0484/1852/1242/files/wezosowadefonarowavebaz.pdf
- https://cdn.shopify.com/s/files/1/0476/7544/1318/files/likeness_of_oryx_week.pdf
- https://cdn.shopify.com/s/files/1/0479/4459/7671/files/rozedaxujufa.pdf
- https://cdn.shopify.com/s/files/1/0431/8268/6367/files/genie_1028_owners_manual.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1036880.mozfiles.com
- site-1038317.mozfiles.com
- site-1039689.mozfiles.com
- site-1037057.mozfiles.com
- cdn.shopify.com
- files.wisemountainyoga.com
- files.villatesoristjohn.com
- files.differentstrokes-painting.com
- files.mnmsprinkler.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report