SUSPICIOUS — gewunuxim_kexoxatuzuko_kejazure.pdf
SUSPICIOUS — gewunuxim_kexoxatuzuko_kejazure.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0b5361310f3483f1fe6ce7bc445492e164e456516ac69d4d07df4a43c0ea20a0 - SHA-1:
692fba848682defd6e2d62973e3ef4aa09ec343f - MD5:
9cbdbe9f82d0a0abaf9faf0465557857 - ssdeep:
768:SgGzpDtp7jrIs7fLSQxt7wktu3XfdS3/LPBUfEvLNi1x2qnsVhdpE:PGF5pDhGXf0dDvLNeQvdpE - TLSH:
T1EA329DF754ABDD0C6AC79F53ACAA2869258AC38C7136976044C8772CC47C7BCBE10960 - Submitted as: gewunuxim_kexoxatuzuko_kejazure.pdf
- File type: pdf · Size: 46979 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/9b439b38-8d57-46ef-b8e0-21578c760bc0/kejaxodadepesixas.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=sintrom%20amann%20girrbach%20pdf, https://cdn-cms.f-static.net/uploads/4366055/normal_5f88168f6d411.pdf, https://cdn-cms.f-static.net/uploads/4368496/normal_5f87b4c641415.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=sintrom%20amann%20girrbach%20pdf
- https://cdn-cms.f-static.net/uploads/4366055/normal_5f88168f6d411.pdf
- https://cdn-cms.f-static.net/uploads/4368496/normal_5f87b4c641415.pdf
- https://cdn-cms.f-static.net/uploads/4378848/normal_5f8d251231298.pdf
- https://cdn-cms.f-static.net/uploads/4365655/normal_5f8728b437e1e.pdf
- https://cdn-cms.f-static.net/uploads/4383924/normal_5f901195cf938.pdf
- https://uploads.strikinglycdn.com/files/ceb1f108-5773-4977-9fbe-393d9fdf59dc/denedap.pdf
- https://uploads.strikinglycdn.com/files/a12e4406-e8a5-485f-8e1e-b0045d10f24a/paluxugevob.pdf
- https://uploads.strikinglycdn.com/files/94fd4da7-f835-4c88-9992-7c3b807ffe98/bonorusifakurepugopesade.pdf
- https://uploads.strikinglycdn.com/files/9b439b38-8d57-46ef-b8e0-21578c760bc0/kejaxodadepesixas.pdf
- https://s3.amazonaws.com/pazifetanegapu/9135525295.pdf
- https://s3.amazonaws.com/widiku/apocrifos_del_antiguo_testamento_v.pdf
- https://tunimesepet.weebly.com/uploads/1/3/1/4/131455680/a7b951a477a4.pdf
- https://goduvozimaku.weebly.com/uploads/1/3/1/3/131380582/5041767.pdf
- https://murudogukezopo.weebly.com/uploads/1/3/4/3/134320821/mikegukawezago.pdf
- https://wefamojugibe.weebly.com/uploads/1/3/1/1/131164519/dosarone_nemamume.pdf
- https://guferewefozitak.weebly.com/uploads/1/3/4/3/134393558/9627616.pdf
- https://lesofetu.weebly.com/uploads/1/3/1/3/131378838/zilowagosabove.pdf
- https://xalipifizipig.weebly.com/uploads/1/3/1/3/131379045/ditetapewexodofa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- s3.amazonaws.com
- tunimesepet.weebly.com
- goduvozimaku.weebly.com
- murudogukezopo.weebly.com
- wefamojugibe.weebly.com
- guferewefozitak.weebly.com
- lesofetu.weebly.com
- xalipifizipig.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report