SUSPICIOUS — loxujojotufonef-muselub.pdf
SUSPICIOUS — loxujojotufonef-muselub.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0fbd62bf2b9eec824064b4e10765e36c02ce5ef0294b387f2e1cdf3b35fa2063 - SHA-1:
1f01e0f3b70bbacdddcb667b7dc0115e4afa28c9 - MD5:
c8242c798118e7549993171679a3aeb7 - ssdeep:
768:1gGzpDdeeceeQwJSMO+aHJ32mUHENbN7y6hRyZc+eR1HTJ:mGFhe7PYmmUHENbNjAZc+enHTJ - TLSH:
T1DE316BF71097DD8C7A8B9B13AEBB242C518ADB892032976041987B2CC47C7AD7F40991 - Submitted as: loxujojotufonef-muselub.pdf
- File type: pdf · Size: 40911 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/4377cc16-191b-41eb-a6da-45b7cd479634/40994040907.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=realtek%20pcie%20gbe%20family%20controller%20c, https://uploads.strikinglycdn.com/files/4377cc16-191b-41eb-a6da-45b7cd479634/40994040907.pdf, https://uploads.strikinglycdn.com/files/5999f6a0-4954-4ac6-af7b-20ca24b12f22/32447571257.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=realtek%20pcie%20gbe%20family%20controller%20c
- https://uploads.strikinglycdn.com/files/4377cc16-191b-41eb-a6da-45b7cd479634/40994040907.pdf
- https://uploads.strikinglycdn.com/files/5999f6a0-4954-4ac6-af7b-20ca24b12f22/32447571257.pdf
- https://uploads.strikinglycdn.com/files/cbc255ab-aac4-4981-8aa2-c79028fe8c21/tawolurifumuwakopefevo.pdf
- https://uploads.strikinglycdn.com/files/bff8632d-902a-4b73-a53d-53f7e24d03a0/vovedojotoziwanolimejo.pdf
- https://uploads.strikinglycdn.com/files/1b063667-52dc-4313-a269-0a904ea9479d/19248141022.pdf
- https://cdn-cms.f-static.net/uploads/4365551/normal_5f8b4d6c143dd.pdf
- https://cdn-cms.f-static.net/uploads/4370064/normal_5f888a6240760.pdf
- https://cdn-cms.f-static.net/uploads/4366978/normal_5f8d34c04ac40.pdf
- https://uploads.strikinglycdn.com/files/578f5418-975d-4496-8023-294965d3ee4c/53125680762.pdf
- https://uploads.strikinglycdn.com/files/68114018-5e75-463f-ba8f-c11c85490cd5/13729343782.pdf
- https://uploads.strikinglycdn.com/files/6462bc24-1270-4c64-bc66-89838642da74/85360468367.pdf
- https://uploads.strikinglycdn.com/files/371dd795-64ef-4fea-97e6-d62205755e79/11443873328.pdf
- https://uploads.strikinglycdn.com/files/e7c0b824-9fa1-44ea-b31f-777ae3533abb/87211535012.pdf
- https://uploads.strikinglycdn.com/files/3967473f-2e34-4cc7-86cd-721a12f546ea/zaworezixirep.pdf
- https://uploads.strikinglycdn.com/files/acaf77f9-d851-4750-8a39-669ac2938b4d/63684555946.pdf
- https://uploads.strikinglycdn.com/files/74603127-dbcf-4f26-8b0f-43322ee9455d/pusedakavijig.pdf
- https://uploads.strikinglycdn.com/files/adfb37c1-fe5f-448f-aeca-efe29c03c3e1/wuvolanoxawevowodejemezuz.pdf
- https://cdn-cms.f-static.net/uploads/4366978/normal_5f8742382f077.pdf
- https://cdn-cms.f-static.net/uploads/4376374/normal_5f8b4cf8402b4.pdf
- https://cdn-cms.f-static.net/uploads/4365591/normal_5f8bfd09220ad.pdf
- https://cdn-cms.f-static.net/uploads/4374843/normal_5f8a94fbd2b45.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report