SUSPICIOUS — 80728367804.pdf
SUSPICIOUS — 80728367804.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
dfc53f6f8d1105840920d8643e9261b39249953004f958e320a822dc15777d24 - SHA-1:
879f671942b97298a4c57f2a050ab511014f1193 - MD5:
2446358600a9b49b1234c484d504b562 - ssdeep:
768:y1gGzpDUu0RSbDBIG6JADonwRPXsIeFlUP1313ZeVIpCVWty+9:ymGFwZSRIT5nw5XsIeFqP13vcIpgmy+9 - TLSH:
T139327CF35067ED8C6B866B83ADA79188705ADB887131EAA044D4B77CC47C2BD5F10E21 - Submitted as: 80728367804.pdf
- File type: pdf · Size: 45472 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://buvomoxiw.mycccamp.org/uploads/1/3/0/9/130969916/ccb60c45ee8f.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=ejercicios+de+lengua+6+primaria+edebe, http://kikub.karenlabeau.com/uploads/1/3/1/0/131070197/risajigotati_monowizi.pdf, http://loxajuw.revibewaverly.com/uploads/1/3/2/6/132695213/e5f5e9510d.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=ejercicios+de+lengua+6+primaria+edebe
- http://kikub.karenlabeau.com/uploads/1/3/1/0/131070197/risajigotati_monowizi.pdf
- http://loxajuw.revibewaverly.com/uploads/1/3/2/6/132695213/e5f5e9510d.pdf
- http://buvomoxiw.mycccamp.org/uploads/1/3/0/9/130969916/ccb60c45ee8f.pdf
- http://gorogupax.voiceoverdoctor.com/uploads/1/3/0/8/130814328/f1aed9.pdf
- https://site-1038653.mozfiles.com/files/1038653/34286998438.pdf
- https://site-1038952.mozfiles.com/files/1038952/sugegigivanarasavuneto.pdf
- https://site-1038700.mozfiles.com/files/1038700/donifenojuxitijutagota.pdf
- http://files.personalspaceproject.com/uploads/1/3/0/9/130969818/wageliwafusovofulol.pdf
- http://tibewod.jbdpta.com/uploads/1/3/2/6/132696558/rukujagidamowoteton.pdf
- http://pusite.theresashealth.com/uploads/1/3/0/7/130775766/vomumibita-biratejobe-xalebodili-zorowagatazugek.pdf
- https://site-1037829.mozfiles.com/files/1037829/15828914373.pdf
- https://site-1039324.mozfiles.com/files/1039324/61087173205.pdf
- https://site-1036934.mozfiles.com/files/1036934/15210428507.pdf
- https://site-1037037.mozfiles.com/files/1037037/88272845138.pdf
- https://site-1037019.mozfiles.com/files/1037019/vigirifa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- kikub.karenlabeau.com
- loxajuw.revibewaverly.com
- buvomoxiw.mycccamp.org
- gorogupax.voiceoverdoctor.com
- site-1038653.mozfiles.com
- site-1038952.mozfiles.com
- site-1038700.mozfiles.com
- files.personalspaceproject.com
- tibewod.jbdpta.com
- pusite.theresashealth.com
- site-1037829.mozfiles.com
- site-1039324.mozfiles.com
- site-1036934.mozfiles.com
- site-1037037.mozfiles.com
- site-1037019.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report