SUSPICIOUS — 52583252208.pdf
SUSPICIOUS — 52583252208.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e15daf3cd345357d98b07c0e74dde2c02d974235123bb5dc6241f34ab7d455eb - SHA-1:
aa049507ef973d8d8966f7987af48296d7476fb2 - MD5:
877463357bee9257c03f5682570189bb - ssdeep:
1536:bGFOOZtkKy3OprO2p86pjVZhu92ddp4EW7S:6FOY3ZprU+jVZ2K4Er - TLSH:
T14034CFF324B7DD8D2A8B9B17AEE624596109D68D60229B70058D772CC87C3FE3D01A60 - Submitted as: 52583252208.pdf
- File type: pdf · Size: 53070 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/e8e4f7c7-cdc3-4fea-8a48-6a94e0daed4c/92812176153.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=watch+the+boys+online+free+fmovies, https://cdn.shopify.com/s/files/1/0266/9556/5482/files/canobie_lake_park_screeemfest_map.pdf, https://uploads.strikinglycdn.com/files/e8e4f7c7-cdc3-4fea-8a48-6a94e0daed4c/92812176153.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=watch+the+boys+online+free+fmovies
- https://cdn.shopify.com/s/files/1/0266/9556/5482/files/canobie_lake_park_screeemfest_map.pdf
- https://uploads.strikinglycdn.com/files/e8e4f7c7-cdc3-4fea-8a48-6a94e0daed4c/92812176153.pdf
- https://cdn.shopify.com/s/files/1/0493/3068/4063/files/guided_camping_tours_australia.pdf
- https://uploads.strikinglycdn.com/files/33398f60-eca3-4098-8f49-e04f5f818153/top_rated_sites_for_airline_tickets.pdf
- https://s3.amazonaws.com/wilugugo/2829321469.pdf
- https://uploads.strikinglycdn.com/files/a1445970-23c7-4521-ba0a-c140623e4dcc/vavofa.pdf
- https://uploads.strikinglycdn.com/files/d04ffc57-6776-42c9-a380-69a181415269/4251869029.pdf
- https://cdn.shopify.com/s/files/1/0500/8539/6643/files/dejopojojiwidubugizo.pdf
- https://s3.amazonaws.com/nawuvud/62683642351.pdf
- https://cdn-cms.f-static.net/uploads/4386620/normal_5f99c0419a3f2.pdf
- https://uploads.strikinglycdn.com/files/ed9ae72d-d1e6-4e6f-8f96-b401109846df/80434223747.pdf
- https://s3.amazonaws.com/fogibi/wunazozifokuvonepalo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report