SUSPICIOUS — 90638649842.pdf
SUSPICIOUS — 90638649842.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e02dc610ac49b7bf8226a08b5f210eb6e6c57bb6c8de7096fada9b841b7675fa - SHA-1:
0778fbd9fa401ce6b533785b3836250262b4cb35 - MD5:
7ffe10b44f36212671e971004b732fdc - ssdeep:
768:+gGzpDi6sOID6KrlbXL/k9czlPVXpMDYRx/IicDRNcvYn6zjGq+gryFuTCVWtj5O:7GFWLeKrxn/DBcDrz2V+uTgmj5O - TLSH:
T10D33AEF35067DCCD3A8AA707ADA71459214ADB4D3262EB6049C47B6CC4BC3FD2E10A61 - Submitted as: 90638649842.pdf
- File type: pdf · Size: 50655 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/8701c8ae-f74b-42aa-ad74-461e6e76177b/34434424915.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=drdo+ceptam+syllabus+2018+pdf, https://site-1036958.mozfiles.com/files/1036958/nididemokozovidasorewe.pdf, https://site-1039506.mozfiles.com/files/1039506/15355911831.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=drdo+ceptam+syllabus+2018+pdf
- https://site-1036958.mozfiles.com/files/1036958/nididemokozovidasorewe.pdf
- https://site-1039506.mozfiles.com/files/1039506/15355911831.pdf
- https://site-1036926.mozfiles.com/files/1036926/45552348128.pdf
- https://site-1038794.mozfiles.com/files/1038794/50056482960.pdf
- https://site-1038810.mozfiles.com/files/1038810/larojilududubalilutagepeb.pdf
- https://uploads.strikinglycdn.com/files/8701c8ae-f74b-42aa-ad74-461e6e76177b/34434424915.pdf
- https://uploads.strikinglycdn.com/files/41d91f54-ebe6-413e-815a-44d2af3df0cc/pipevuke.pdf
- https://uploads.strikinglycdn.com/files/63479e8d-f9fc-4832-b359-f0123a04dce7/diteniwameginuxi.pdf
- https://cdn.shopify.com/s/files/1/0480/2592/7839/files/best_morrowind_combat_mods.pdf
- https://cdn.shopify.com/s/files/1/0434/5082/6905/files/accord_aix_les_bains_maroc_france.pdf
- https://cdn.shopify.com/s/files/1/0435/9376/0931/files/number_theory_solution.pdf
- https://cdn.shopify.com/s/files/1/0440/9327/6312/files/epf_withdrawal_form_19_non_aadhar.pdf
- https://cdn.shopify.com/s/files/1/0438/2847/8102/files/marvel_contest_of_champions_mod_apk.pdf
- https://cdn.shopify.com/s/files/1/0431/7839/3762/files/92575676549.pdf
- https://cdn.shopify.com/s/files/1/0427/4244/8295/files/56465321189.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1036958.mozfiles.com
- site-1039506.mozfiles.com
- site-1036926.mozfiles.com
- site-1038794.mozfiles.com
- site-1038810.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report