SUSPICIOUS — 34418999245.pdf
SUSPICIOUS — 34418999245.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fe62bba7d28fafdeb99f39ea05a7c5c930f914ed3f336654edbe239489e8bb4d - SHA-1:
06c2429c1801d74cbd533f361b5873a2ce5568b0 - MD5:
b290aaa70ffd5a8f33953491b75e8f5f - ssdeep:
3072:lFapfXhyKFjggaL/s485vWS8l1lrJ8XcEByyHnKpB7rSRrrpMefDmkG4w:rEfx9ggK04ivWr8XcHU+WfplikG4w - TLSH:
T1613FF1F38033DE9C7ED29B836AF51958911AD68931325FA44248B62CC8BC3BDAF51D11 - Submitted as: 34418999245.pdf
- File type: pdf · Size: 150365 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://gtconceptsllc.com/uploads/1/3/1/4/131483214/zaturujof_ferenafoxor.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=valoracion+nutricional+del+adulto+mayor+pdf, http://gtconceptsllc.com/uploads/1/3/1/4/131483214/zaturujof_ferenafoxor.pdf, http://baxar.blakkanvas.studio/uploads/1/3/1/1/131164312/berukikav.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=valoracion+nutricional+del+adulto+mayor+pdf
- http://gtconceptsllc.com/uploads/1/3/1/4/131483214/zaturujof_ferenafoxor.pdf
- http://baxar.blakkanvas.studio/uploads/1/3/1/1/131164312/berukikav.pdf
- http://koxuru.ashleyelainecooper.com/uploads/1/3/2/6/132683014/fuvuvurufa-ruwifage-vadaro-xafazapafuke.pdf
- http://files.newspark901.org/uploads/1/3/1/8/131871786/jimesusuxu.pdf
- http://vupaxefed.legacyministries.info/uploads/1/3/1/4/131483245/7674.pdf
- http://damuvi.montrealmusiccamp.com/uploads/1/3/1/3/131378942/5584c409ad3f.pdf
- http://files.btbrv.com/uploads/1/3/1/1/131164174/kawijodawazajupupak.pdf
- http://files.sunshinefitness7953.com/uploads/1/3/0/7/130775911/litumoruluxajovi.pdf
- http://files.litluxurycandleco.com.au/uploads/1/3/1/0/131070374/sowiv.pdf
- http://bubut.susankraftconsulting.com/uploads/1/3/1/4/131437914/9038349.pdf
- https://site-1036812.mozfiles.com/files/1036812/duxutapetoxiwir.pdf
- https://site-1039553.mozfiles.com/files/1039553/67291958826.pdf
- https://site-1036743.mozfiles.com/files/1036743/mupimerupaf.pdf
- https://site-1037207.mozfiles.com/files/1037207/nowon.pdf
- https://site-1036858.mozfiles.com/files/1036858/rawopedulosule.pdf
- http://files.heroicfineartgallery.com/uploads/1/3/1/4/131414561/gunidet_wivenakajejemu_gakuwitege.pdf
- http://filuxo.glynhaynie.net/uploads/1/3/0/7/130739560/zijekegi.pdf
- http://zadoro.francelessart.com/uploads/1/3/1/3/131398455/aac62.pdf
- http://files.nalomelihoney.com/uploads/1/3/1/4/131483170/6336180.pdf
- http://files.meganlamart.com/uploads/1/3/0/8/130874431/mawurodoketew.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- gtconceptsllc.com
- koxuru.ashleyelainecooper.com
- files.newspark901.org
- vupaxefed.legacyministries.info
- damuvi.montrealmusiccamp.com
- files.btbrv.com
- files.sunshinefitness7953.com
- files.litluxurycandleco.com.au
- bubut.susankraftconsulting.com
- site-1036812.mozfiles.com
- site-1039553.mozfiles.com
- site-1036743.mozfiles.com
- site-1037207.mozfiles.com
- site-1036858.mozfiles.com
- files.heroicfineartgallery.com
- filuxo.glynhaynie.net
- zadoro.francelessart.com
- files.nalomelihoney.com
- files.meganlamart.com
- www.w3.org
- purl.org
- ns.adobe.com
- baxar.blakkanvas.studio
File paths
- j:\URV%:
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report