SUSPICIOUS — mass_effect_1_controller_support_power_wheel_1.2.2.pdf
SUSPICIOUS — mass_effect_1_controller_support_power_wheel_1.2.2.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ea9511e8d8743b7a2fb486f83f811ae29a84908855ab7a8e6717aa68d1fed8b9 - SHA-1:
3a16944b03552ce06e2ad6110f1aed28fb4beebf - MD5:
289e336efdbe4b3840f227e4783d4a22 - ssdeep:
1536:9GFJeaM/6jMRMDynJ7qG+tHkNtrrqqcJrGFgbpX6IVPr/QpY/AjD/hc8FQ:AFJe9R77qhHkNtrOquy5CLYjD/hcB - TLSH:
T1CF39CFF728D3DD8C2A47AB13AEB606195189C74D2127EBA016CC662CC4BC67CBF11761 - Submitted as: mass_effect_1_controller_support_power_wheel_1.2.2.pdf
- File type: pdf · Size: 88380 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/331d2f9a-d7a1-43a0-a44c-e29618e46c3f/bonafide_certificate_format_for_scho.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=mass+effect+1+controller+support+%2528power+wheel%2529+1.2.2, https://uploads.strikinglycdn.com/files/331d2f9a-d7a1-43a0-a44c-e29618e46c3f/bonafide_certificate_format_for_scho.pdf, https://uploads.strikinglycdn.com/files/8298e3d8-ac5e-4c99-a905-3899444daac7/47170242775.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=mass+effect+1+controller+support+%2528power+wheel%2529+1.2.2
- https://uploads.strikinglycdn.com/files/331d2f9a-d7a1-43a0-a44c-e29618e46c3f/bonafide_certificate_format_for_scho.pdf
- https://uploads.strikinglycdn.com/files/8298e3d8-ac5e-4c99-a905-3899444daac7/47170242775.pdf
- https://uploads.strikinglycdn.com/files/945b15fe-38cd-48a6-870b-336831f01c10/sekixabetexumide.pdf
- https://uploads.strikinglycdn.com/files/d21712e6-d0c3-428d-a8eb-f300373a73ce/nedaloxep.pdf
- https://uploads.strikinglycdn.com/files/1b9e6f29-c71e-4e60-bb2d-3f8b50db9a07/zerode.pdf
- https://cdn.shopify.com/s/files/1/0438/3696/5026/files/at_play_in_the_fields_of_the_lord_dvd.pdf
- https://cdn.shopify.com/s/files/1/0501/1786/9768/files/beamng_drive_android_oyun_club.pdf
- https://cdn.shopify.com/s/files/1/0432/4563/3693/files/22420711113.pdf
- https://cdn.shopify.com/s/files/1/0434/4666/5382/files/dd_insider_subscription.pdf
- https://uploads.strikinglycdn.com/files/ca1e36ef-70a5-4068-9dc1-dbd48e584cdc/tunomopobufalibesi.pdf
- https://uploads.strikinglycdn.com/files/9a13a8c7-4641-4ff3-b971-0b9a3d47cfca/jupegixugivojobi.pdf
- https://uploads.strikinglycdn.com/files/d1c8ec41-4d23-45e3-944d-a7c0f3192d98/vukezetakokojobok.pdf
- https://uploads.strikinglycdn.com/files/9b17377c-721e-440e-9c86-c58982e3239b/luwazumemune.pdf
- https://uploads.strikinglycdn.com/files/e16a568f-79b9-4f60-aacc-ce0d5a71d7bb/fisizabepifowalozaniteg.pdf
- https://uploads.strikinglycdn.com/files/a3040b5b-4a3d-467c-bf0c-9834df12d73b/referencias_personales_solicitud_de_empleo.pdf
- https://uploads.strikinglycdn.com/files/b63defd5-a834-425c-909e-fad9049d43e0/82956917616.pdf
- https://uploads.strikinglycdn.com/files/c66ad501-6a67-400e-9696-61c47289843b/miwovilijenen.pdf
- https://cdn.shopify.com/s/files/1/0433/5176/9256/files/sesumisijujaboxuxa.pdf
- https://cdn.shopify.com/s/files/1/0433/1952/5534/files/37398446247.pdf
- https://cdn.shopify.com/s/files/1/0434/0780/2518/files/red_cabbage_lab_answers.pdf
- https://cdn.shopify.com/s/files/1/0437/1188/9573/files/pibovosap.pdf
- https://cdn.shopify.com/s/files/1/0484/8857/9233/files/onn_wall_mount_glass_shelf.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report