SUSPICIOUS — 14534724045.pdf
SUSPICIOUS — 14534724045.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f95123e8550b3e268e2ab6949ee3d0146226a4065542eafde88f90df51b28d5e - SHA-1:
9afed37a689f9723e495030a67913a31f6f4e4ca - MD5:
c5b8b0ad820347996cdcd14679e2ffc6 - ssdeep:
768:+gGzpD4NRW+xg6GGE/O6roWnfPR7LjKtGpnW9lEomntBmw:7GFsNsygDGE/wAPR7LGEpnW9lENntBmw - TLSH:
T143338EF310A7DD8C7A8E9B4799EB146DA046D789713396E058D8772C80BCBBD2E00A51 - Submitted as: 14534724045.pdf
- File type: pdf · Size: 47874 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://files.nw-churchofchrist.com/uploads/1/3/2/7/132710763/zixexojifipeb.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=fnaf+texture+pack+1.13.2, http://files.nw-churchofchrist.com/uploads/1/3/2/7/132710763/zixexojifipeb.pdf, http://files.bayviewveterinary.net/uploads/1/3/1/6/131606248/2501650.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=fnaf+texture+pack+1.13.2
- http://files.nw-churchofchrist.com/uploads/1/3/2/7/132710763/zixexojifipeb.pdf
- http://files.bayviewveterinary.net/uploads/1/3/1/6/131606248/2501650.pdf
- http://pebogu.casadegatodesigns.com/uploads/1/3/1/6/131637432/depojavaboda.pdf
- http://vifut.tricityanimalclinic.com/uploads/1/3/0/8/130874493/malozosivatigamo.pdf
- http://files.poitrading.com/uploads/1/3/1/3/131383543/butowepot_jozasigi.pdf
- https://uploads.strikinglycdn.com/files/65bc2bca-4cb8-4439-931d-dce5a42bab44/39895648051.pdf
- https://uploads.strikinglycdn.com/files/1fb11c3d-74a5-4517-a8b3-6d50bc39b483/xesusivegonanofelaz.pdf
- https://uploads.strikinglycdn.com/files/41d1c05a-fa31-4007-b6e6-2c20a2e60049/32420132288.pdf
- https://site-1043248.mozfiles.com/files/1043248/56451188408.pdf
- https://site-1038938.mozfiles.com/files/1038938/17299133707.pdf
- https://site-1036944.mozfiles.com/files/1036944/42572159805.pdf
- https://site-1040400.mozfiles.com/files/1040400/12558243166.pdf
- https://site-1037866.mozfiles.com/files/1037866/57077343830.pdf
- https://uploads.strikinglycdn.com/files/b1b95c09-284a-4a0e-9cb1-b7a5b6c799cc/12425292772.pdf
- https://uploads.strikinglycdn.com/files/7e1a9a1c-2f98-4439-aed2-35998375d3f7/pisogejamapa.pdf
- https://uploads.strikinglycdn.com/files/aed6d914-b3a5-45b1-85e2-76e18750a28d/mafakameligisosu.pdf
- https://uploads.strikinglycdn.com/files/d95aa154-319f-4fe8-a4fa-c947db8dd883/rojoxeketinizowimame.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- files.nw-churchofchrist.com
- files.bayviewveterinary.net
- pebogu.casadegatodesigns.com
- vifut.tricityanimalclinic.com
- files.poitrading.com
- uploads.strikinglycdn.com
- site-1043248.mozfiles.com
- site-1038938.mozfiles.com
- site-1036944.mozfiles.com
- site-1040400.mozfiles.com
- site-1037866.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report