SUSPICIOUS — 14930257493.pdf
SUSPICIOUS — 14930257493.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f9d2541976092ac435fb39e6564f74767697bee5ec75147d5365ff9f28b87510 - SHA-1:
2fbea8a39ef8e2ceedeb9ade178f96b5b664c34d - MD5:
d4175a33633af40bd9a1e758a626464f - ssdeep:
768:1gGzpDoiLyokVi1fbFNV7P/fW4o1GpT7EjNbjDZAgbvig2kFF:mGFUi5p3fWdGV743lAKvskFF - TLSH:
T102319EF31057ED4C7E8A1F03AEAB019A9149C78C7136A7A059CC766CD4B86FD6F00A64 - Submitted as: 14930257493.pdf
- File type: pdf · Size: 42969 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/9640bd00-796f-465b-b68a-314cde3b981e/60389893496.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=nombres+para+equipos+de+mujeres, https://uploads.strikinglycdn.com/files/6c36e5b0-9ab0-4b91-bd0c-77e9d8777b2a/45830228259.pdf, https://uploads.strikinglycdn.com/files/c302928e-8cd7-4063-8310-c9b7a10b7a2c/22367166257.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=nombres+para+equipos+de+mujeres
- https://uploads.strikinglycdn.com/files/6c36e5b0-9ab0-4b91-bd0c-77e9d8777b2a/45830228259.pdf
- https://uploads.strikinglycdn.com/files/c302928e-8cd7-4063-8310-c9b7a10b7a2c/22367166257.pdf
- https://uploads.strikinglycdn.com/files/f1bc699c-d1c1-47f9-b585-8912025dea62/90642321700.pdf
- https://uploads.strikinglycdn.com/files/f771c288-ff25-40cd-8eba-c01046c2a940/45734189613.pdf
- https://uploads.strikinglycdn.com/files/9640bd00-796f-465b-b68a-314cde3b981e/60389893496.pdf
- https://cdn.shopify.com/s/files/1/0485/9733/6224/files/10000_watt_inverter_price_in_india.pdf
- https://cdn.shopify.com/s/files/1/0483/1618/6779/files/48369467485.pdf
- https://cdn.shopify.com/s/files/1/0439/6164/7262/files/40738277868.pdf
- https://cdn.shopify.com/s/files/1/0499/8637/1752/files/gosit.pdf
- https://cdn.shopify.com/s/files/1/0485/0194/8577/files/zipenitudibit.pdf
- http://files.kidsonup.com/uploads/1/3/1/8/131856992/zufutigizuvo_najupidetuxazi.pdf
- http://files.simonpachano.com/uploads/1/3/1/3/131379045/fc747c210b7.pdf
- http://files.premiumrvtrader.com/uploads/1/3/1/0/131070798/lamobikinapikuretezu.pdf
- http://files.unpsoccer.org/uploads/1/3/2/3/132302732/8982865.pdf
- https://site-1042509.mozfiles.com/files/1042509/mumosubeko.pdf
- https://site-1039772.mozfiles.com/files/1039772/besigigived.pdf
- https://site-1037897.mozfiles.com/files/1037897/78824210234.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- files.kidsonup.com
- files.simonpachano.com
- files.premiumrvtrader.com
- files.unpsoccer.org
- site-1042509.mozfiles.com
- site-1039772.mozfiles.com
- site-1037897.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report