SUSPICIOUS — refuledizevukevuvogu.pdf
SUSPICIOUS — refuledizevukevuvogu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0b1d6e69bda3ae179a1891506259ae0425e894dc6482b5a144aedd654311c2c4 - SHA-1:
a6886f7076298216315dab2f74b47c2b57adeb96 - MD5:
78fd80067cce946f7bdd3f668f6cc3d3 - ssdeep:
768:qgGzpDkpTFPpl6rF+HNSkvgIh6zbfqg0xcuugXF:3GFopHQkvgO6zbJruugXF - TLSH:
T18E307CF711D7EC8C3A8B6B03AEA70068558ED38D61279770018C776DC4BCAAD7E10A65 - Submitted as: refuledizevukevuvogu.pdf
- File type: pdf · Size: 37241 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/bbdbf282-5ab4-4382-9a12-44525cba48e1/87958432669.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=steven+universe+concept+art+book+pdf, https://uploads.strikinglycdn.com/files/bbdbf282-5ab4-4382-9a12-44525cba48e1/87958432669.pdf, https://uploads.strikinglycdn.com/files/6621068e-6540-4b97-bdde-3491da6023c4/19801085550.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=steven+universe+concept+art+book+pdf
- https://uploads.strikinglycdn.com/files/bbdbf282-5ab4-4382-9a12-44525cba48e1/87958432669.pdf
- https://uploads.strikinglycdn.com/files/6621068e-6540-4b97-bdde-3491da6023c4/19801085550.pdf
- https://uploads.strikinglycdn.com/files/c650facf-0959-44a2-a7fc-a7a80b50eae4/76484984043.pdf
- https://uploads.strikinglycdn.com/files/368d2e81-52e3-4735-b970-73c75bc84e96/pejepopakoboliferumemo.pdf
- https://uploads.strikinglycdn.com/files/f811ac80-e186-4467-ac4e-825d897eaf3d/revinadagavax.pdf
- https://cdn-cms.f-static.net/uploads/4367622/normal_5f8b5bfe2090b.pdf
- https://cdn-cms.f-static.net/uploads/4366325/normal_5f8a8e836c194.pdf
- https://uploads.strikinglycdn.com/files/8e9fbf2a-8e28-421b-98e5-e8dfb53d9768/20855084242.pdf
- https://uploads.strikinglycdn.com/files/929df6d3-8b2b-47b7-aa41-f7674fda5393/busudumo.pdf
- https://cdn-cms.f-static.net/uploads/4367271/normal_5f89e92556ab5.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f8b52781755e.pdf
- https://cdn-cms.f-static.net/uploads/4368469/normal_5f889af3bc9fb.pdf
- https://cdn-cms.f-static.net/uploads/4366630/normal_5f89ffa54bf21.pdf
- https://gaxopekel.weebly.com/uploads/1/3/0/9/130969853/merituf.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/7885719.pdf
- https://xibogunef.weebly.com/uploads/1/3/1/3/131398295/d398302424aa.pdf
- https://uploads.strikinglycdn.com/files/3e8e6a43-f6e5-4f7d-8c41-59cae09e562d/ferizesunitefodavuvixowas.pdf
- https://uploads.strikinglycdn.com/files/ac9b3818-5295-4100-a345-c86224bf2343/gapavigedafuwenipeke.pdf
- https://uploads.strikinglycdn.com/files/6d4c5ca6-6030-479b-a559-0fe5b9673662/24611403920.pdf
- https://uploads.strikinglycdn.com/files/909810f7-9d0f-4378-ab19-1ea4ffc86b92/ejercicios_de_distinguir_pronombres_y_determinantes.pdf
- https://uploads.strikinglycdn.com/files/b4fe40c8-18ab-46c0-a6ac-c560308cf4bc/rejab.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- gaxopekel.weebly.com
- keniwuki.weebly.com
- xibogunef.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report