SUSPICIOUS — 22951999377.pdf
SUSPICIOUS — 22951999377.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f9f8516c167eb556de46a139274f8d0a8e5d101428621151210f2a0c4cfc7ee9 - SHA-1:
2a37b5151a13a10378e0f35eecbdf841a9b780a0 - MD5:
53be64f43627597c9260dee744535fff - ssdeep:
1536:MGFjzgM7yZZ/4k9nJ0QEb+CTx4kwcrEWQeDt:pFjzgM2Zak1lCGarMy - TLSH:
T1FD35AFF34097DDC87EC3EB87A9560458B54ADA4C6133A7A09898776CC4BC2BCBF11960 - Submitted as: 22951999377.pdf
- File type: pdf · Size: 58025 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/8cccfad4-9af0-4f8f-bbc7-fad09d07430d/47903958784.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=chokher+bali+full+movie+in+hindi+part+1, https://uploads.strikinglycdn.com/files/8cccfad4-9af0-4f8f-bbc7-fad09d07430d/47903958784.pdf, https://uploads.strikinglycdn.com/files/f2ebe878-5f39-4bad-bba0-dd0346a8fc05/9354991432.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=chokher+bali+full+movie+in+hindi+part+1
- https://uploads.strikinglycdn.com/files/8cccfad4-9af0-4f8f-bbc7-fad09d07430d/47903958784.pdf
- https://uploads.strikinglycdn.com/files/f2ebe878-5f39-4bad-bba0-dd0346a8fc05/9354991432.pdf
- https://uploads.strikinglycdn.com/files/a54c4782-3e2c-4b00-9e58-c43752c42247/lotuwujekorevesawunolega.pdf
- https://uploads.strikinglycdn.com/files/c45ee384-6969-4f61-ba89-a45e5ee19b52/12445637287.pdf
- https://uploads.strikinglycdn.com/files/31061c04-4acb-40bd-856f-bc172ad42631/xekinopebujusifazuwek.pdf
- https://uploads.strikinglycdn.com/files/93f9ae0c-4d2c-4cf8-a96c-19aaa13f0a37/guzofinixuvugupidap.pdf
- http://wowakaji.serenaashley.com/uploads/1/3/1/6/131606577/lugowolaperimet.pdf
- http://dajom.jar-labs.vomifix.com/uploads/1/3/0/8/130873952/1756023.pdf
- http://rolelu.aflskincare.com/uploads/1/3/0/7/130740166/71fb1e292.pdf
- http://sagibagom.soulrecoveryandalusia.com/uploads/1/3/1/4/131453284/5919024.pdf
- http://kijuwobe.acrylicandink.com/uploads/1/3/1/8/131857243/kobelenibenol.pdf
- http://files.chicouta.org/uploads/1/3/1/4/131406202/1950830.pdf
- http://files.literacyladder.net/uploads/1/3/0/9/130969993/1962984.pdf
- http://bepikogol.ohslmc.com/uploads/1/3/0/9/130969449/2868436.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- wowakaji.serenaashley.com
- dajom.jar-labs.vomifix.com
- rolelu.aflskincare.com
- sagibagom.soulrecoveryandalusia.com
- kijuwobe.acrylicandink.com
- files.chicouta.org
- files.literacyladder.net
- bepikogol.ohslmc.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report