MALICIOUS — putatukeni.pdf
MALICIOUS — putatukeni.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1048d8601d344ef57716bb47d48305a32035c2b095d7cee3299b6d5249fec538 - SHA-1:
dea6cb193c6df6bd58bf542929ddde4811965fd0 - MD5:
10b90f6ff3277a8c5d23a56c65325c38 - ssdeep:
768:egGzpDcVYa/OoutI2dUKFaEYBhIHzBS4ZoTayIbTI8ag/XddtNH1AwcR+32z:bGFY+adut9dQjBhQoTabI8zrX1A9R+3A - TLSH:
T184319EF340A7EE4CBA8AEB076DE615599189D78C2123976004CC376DC5BC2BD7E10960 - Submitted as: putatukeni.pdf
- File type: pdf · Size: 42487 bytes
- Verdict: malicious (75/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/4daef8cc-b9ec-4be0-89e2-5fbd1f1f1cc8/10003171389.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=noun+verb+adjective+adverb+form+of+words+pdf, https://uploads.strikinglycdn.com/files/d13673df-324e-4108-8537-8ede82c16974/70937675632.pdf, https://uploads.strikinglycdn.com/files/8e90a3fd-44d9-4214-9896-4bfe32a14cb5/sirezijumosogarovemu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=noun+verb+adjective+adverb+form+of+words+pdf
- https://uploads.strikinglycdn.com/files/d13673df-324e-4108-8537-8ede82c16974/70937675632.pdf
- https://uploads.strikinglycdn.com/files/8e90a3fd-44d9-4214-9896-4bfe32a14cb5/sirezijumosogarovemu.pdf
- https://uploads.strikinglycdn.com/files/6d11f74a-99ad-4d9d-a166-226bb4f06f44/62747326045.pdf
- https://uploads.strikinglycdn.com/files/40bd7c2e-b7b7-4526-a397-43f614253fbe/46068379140.pdf
- https://uploads.strikinglycdn.com/files/3b1ddbb4-264c-4064-925f-d9728577d9f9/76273412806.pdf
- https://uploads.strikinglycdn.com/files/4daef8cc-b9ec-4be0-89e2-5fbd1f1f1cc8/10003171389.pdf
- https://uploads.strikinglycdn.com/files/95bd9b8a-e9dd-4f99-ad98-9d35ba7c702d/juweravosekodazikitetuwo.pdf
- https://uploads.strikinglycdn.com/files/5a48200b-5880-4a20-bc16-5dfff3168e1b/11113126999.pdf
- https://uploads.strikinglycdn.com/files/3ce19eb8-f1bc-4f99-941d-c0c6996d7487/95552553421.pdf
- https://site-1036944.mozfiles.com/files/1036944/melizogosak.pdf
- https://site-1039190.mozfiles.com/files/1039190/lemirewewafokuzuluvem.pdf
- https://site-1036871.mozfiles.com/files/1036871/mukidiri.pdf
- https://site-1036871.mozfiles.com/files/1036871/82615889740.pdf
- https://cdn.shopify.com/s/files/1/0464/9654/6984/files/emmener_apporter_emporter_emmener_exercices.pdf
- https://cdn.shopify.com/s/files/1/0464/7380/5982/files/minecraft_apk_for_pc_softonic.pdf
- https://cdn.shopify.com/s/files/1/0438/0377/1041/files/coordinate_geometry_worksheet_for_class_10.pdf
- https://cdn.shopify.com/s/files/1/0435/3074/8055/files/angular_6_file_from_url.pdf
- https://cdn.shopify.com/s/files/1/0429/0809/0535/files/95543096575.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1036944.mozfiles.com
- site-1039190.mozfiles.com
- site-1036871.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report