SUSPICIOUS — 65763003922.pdf
SUSPICIOUS — 65763003922.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e92b8e2f75d57bea78ed39a8b668d2fbc454df1365589b4806b4d958c6ea5dbd - SHA-1:
093aa09623948e72e4f516f37af0c195f257f80c - MD5:
a370f8f0b0458f77f68b5195b6672860 - ssdeep:
768:kgGzpD+uq5BX0eGWXb8b85Ltce25uD5yVPF5sWDdJtQ6tvLW34TSanPPFhaXSpbx:RGF6TnXb8455uDJLbPPFdhwHU7sWU4 - TLSH:
T15236BFF31097DC8C7A8FAF0B6EA711596189C2C86176D3A051887B7CC67C2ED3E21A11 - Submitted as: 65763003922.pdf
- File type: pdf · Size: 64333 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://files.prismnyc.org/uploads/1/3/2/6/132695329/vujuxadixane.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=mortal+kombat+3+game+gear, http://files.mommalovesyou.net/uploads/1/3/0/8/130814329/nexawawevoboli-betivevizivup-vatipasujati-vumenexokawozus.pdf, http://fubivare.skateteamindy.com/uploads/1/3/2/3/132303093/f6d1d9cb9afd4be.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=mortal+kombat+3+game+gear
- http://files.mommalovesyou.net/uploads/1/3/0/8/130814329/nexawawevoboli-betivevizivup-vatipasujati-vumenexokawozus.pdf
- http://fubivare.skateteamindy.com/uploads/1/3/2/3/132303093/f6d1d9cb9afd4be.pdf
- http://files.prismnyc.org/uploads/1/3/2/6/132695329/vujuxadixane.pdf
- http://pegila.rainwaterfarmsny.com/uploads/1/3/1/1/131164273/dotinipemawe.pdf
- http://files.therenegadeorganization.com/uploads/1/3/0/7/130776120/zifura.pdf
- https://uploads.strikinglycdn.com/files/053bbedb-f10c-49bf-ab45-9c688520edff/55024921058.pdf
- https://uploads.strikinglycdn.com/files/62da8386-3c03-4805-84bc-c5de7a979996/21467854745.pdf
- https://uploads.strikinglycdn.com/files/b9d27172-f609-4e60-80a9-ee24498981ee/mejitawobaw.pdf
- https://uploads.strikinglycdn.com/files/826b0a2c-77b7-4c15-b628-417d753c3af7/21322547200.pdf
- http://mabisi.theyellowsunstudio.com/uploads/1/3/2/6/132682829/somonuke-nesofegafev.pdf
- http://rufun.iheartthrift.com/uploads/1/3/1/4/131407405/3546431.pdf
- http://files.trinity-swarthmore.org/uploads/1/3/0/8/130814124/xitazavosonixedon.pdf
- http://files.coachweston.com/uploads/1/3/1/4/131453267/df74f66a39.pdf
- http://files.muniss.de/uploads/1/3/1/4/131409135/a05b52fc39ad40b.pdf
- https://site-1038526.mozfiles.com/files/1038526/bugegasowuted.pdf
- https://site-1039207.mozfiles.com/files/1039207/xinifawusidojorogejisugo.pdf
- https://site-1037835.mozfiles.com/files/1037835/fafogivawajogan.pdf
- https://site-1036798.mozfiles.com/files/1036798/kowarejedebufipi.pdf
- https://site-1037094.mozfiles.com/files/1037094/jamoga.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- files.mommalovesyou.net
- fubivare.skateteamindy.com
- files.prismnyc.org
- pegila.rainwaterfarmsny.com
- files.therenegadeorganization.com
- uploads.strikinglycdn.com
- mabisi.theyellowsunstudio.com
- rufun.iheartthrift.com
- files.trinity-swarthmore.org
- files.coachweston.com
- files.muniss.de
- site-1038526.mozfiles.com
- site-1039207.mozfiles.com
- site-1037835.mozfiles.com
- site-1036798.mozfiles.com
- site-1037094.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report