SUSPICIOUS — adiemus_enya_free.pdf
SUSPICIOUS — adiemus_enya_free.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0c73ecf89bf193c33a39aac80020186fa8e7ada0a1c8e59d6b816e8073369e6d - SHA-1:
992ad071d731db9092530a4151299c16e14fa57c - MD5:
6b055505f8fdade52ad86a3ae614d018 - ssdeep:
768:zgGzpDnpVV0bTSrqHN/4EviJHJ3xLgcMXzfrrXPteSb7d:MGFbpVMN4E41gcMTfXlbd - TLSH:
T144305AF314D7ED8C7E8AAB13A9AB2159504AC34DA13AEB6054CC762DC4BC67DBF00851 - Submitted as: adiemus_enya_free.pdf
- File type: pdf · Size: 38065 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/aaaa1fff-1168-4c8d-a616-32ab792368e8/jumibafasazibitemuzu.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=adiemus+enya++free, https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/lanadez.pdf, https://pumowurunumig.weebly.com/uploads/1/3/2/7/132740285/b37f31.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=adiemus+enya++free
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/lanadez.pdf
- https://pumowurunumig.weebly.com/uploads/1/3/2/7/132740285/b37f31.pdf
- https://wekubuzebebam.weebly.com/uploads/1/3/0/7/130739705/kezakavukojeg.pdf
- https://lipowuripipu.weebly.com/uploads/1/3/1/3/131378852/ninanikixaleza_fidunagi_ruvetafabona_nojaropef.pdf
- https://uploads.strikinglycdn.com/files/aaaa1fff-1168-4c8d-a616-32ab792368e8/jumibafasazibitemuzu.pdf
- https://uploads.strikinglycdn.com/files/2543fab0-3c5c-410d-b04b-c58a2af19695/luvujamufebi.pdf
- https://cdn-cms.f-static.net/uploads/4368955/normal_5f886b167af19.pdf
- https://cdn-cms.f-static.net/uploads/4369908/normal_5f89758b5492d.pdf
- https://cdn-cms.f-static.net/uploads/4368752/normal_5f890fcf96bde.pdf
- https://uploads.strikinglycdn.com/files/4e11beed-e98a-4430-a2a7-eb1d0b83d17c/bumuganoluvototo.pdf
- https://uploads.strikinglycdn.com/files/de3b44eb-80f6-44ff-b8f2-dd5bb2aea72b/lufokig.pdf
- https://uploads.strikinglycdn.com/files/3ab4eb79-a25d-4e94-a356-9c6d4eabb201/55438683190.pdf
- https://uploads.strikinglycdn.com/files/c91ec324-845e-4aaa-ba7c-4f408020955d/84016438872.pdf
- https://uploads.strikinglycdn.com/files/5bd971d7-8f46-4803-a5cb-f7871cbd0b0e/80973560583.pdf
- https://uploads.strikinglycdn.com/files/f4363939-d2c6-409f-9e15-3ad29749fcdf/jiwutovesufitid.pdf
- https://uploads.strikinglycdn.com/files/68e2d7da-c48e-4c24-9579-2b53e599525f/18172754529.pdf
- https://uploads.strikinglycdn.com/files/0930542c-e141-4637-abf3-2917b37d6b6f/dosuna.pdf
- https://uploads.strikinglycdn.com/files/c75b834d-d124-4fe3-89e7-7a786473fc1c/46875697711.pdf
- https://uploads.strikinglycdn.com/files/6d7b3504-8e6c-4371-ace4-58d6d321de5e/54809987835.pdf
- https://uploads.strikinglycdn.com/files/bbe00af7-b896-4b97-a524-a38358aac8f8/41197647503.pdf
- https://uploads.strikinglycdn.com/files/fcbac8ab-e9eb-4a2a-9da8-a7086c78a678/72179352367.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- guwomenod.weebly.com
- pumowurunumig.weebly.com
- wekubuzebebam.weebly.com
- lipowuripipu.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report