SUSPICIOUS — senazerat.pdf
SUSPICIOUS — senazerat.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1b279650b5b4e25914f2da7b7c1fb96a396839b5d5666ca6ddadf023eb2c6af8 - SHA-1:
3c801a6f6c719b5b4a376af8af7005568a46176f - MD5:
c83ea8bd4c74d030922b17a05671ee5a - ssdeep:
768:SgGzpDitCc/prnCgDFHru9bh6NBo9ZxZaoWAez8MxQcwMJ833ZB/:PGFmlHru/c+h1Wn8MW+833L/ - TLSH:
T1C732AEF394A7EC8C7A875B439DEA0159618ED6882132A77088C8377CC4BC5BE7E10970 - Submitted as: senazerat.pdf
- File type: pdf · Size: 43256 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/b227dd7d-3472-405b-b2b4-8c33746cbab4/jiwenixalutifa.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=migrate+exchange+2010+to+office+365+step+by+step+pdf, https://site-1037172.mozfiles.com/files/1037172/49686605277.pdf, https://site-1037189.mozfiles.com/files/1037189/48012021958.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=migrate+exchange+2010+to+office+365+step+by+step+pdf
- https://site-1037172.mozfiles.com/files/1037172/49686605277.pdf
- https://site-1037189.mozfiles.com/files/1037189/48012021958.pdf
- https://site-1036711.mozfiles.com/files/1036711/vinapogupaziwajufafazisuw.pdf
- https://site-1037125.mozfiles.com/files/1037125/worugozarexiwegot.pdf
- https://site-1036649.mozfiles.com/files/1036649/bezavimabosuja.pdf
- https://cdn.shopify.com/s/files/1/0436/3865/3086/files/lucy_daughter_of_the_devil.pdf
- https://cdn.shopify.com/s/files/1/0431/9671/1069/files/56_oz_equals_to_cups.pdf
- https://cdn.shopify.com/s/files/1/0428/8774/1599/files/8478579813.pdf
- https://cdn.shopify.com/s/files/1/0434/7897/4629/files/kazonejisagosasedipuwos.pdf
- https://uploads.strikinglycdn.com/files/b227dd7d-3472-405b-b2b4-8c33746cbab4/jiwenixalutifa.pdf
- https://uploads.strikinglycdn.com/files/d97fb8dc-5154-44b4-979a-5f1bc345fbdf/kowoluzes.pdf
- https://uploads.strikinglycdn.com/files/15ec8421-13f4-47f5-ba04-e7b8b6882e91/tefidejebigemazuzif.pdf
- https://uploads.strikinglycdn.com/files/21351be8-3d03-4e5b-8780-14c27f70039c/81062507346.pdf
- https://uploads.strikinglycdn.com/files/bb766fc3-3305-4fc4-87e5-ad3ccecd7ec2/65055869551.pdf
- https://site-1037160.mozfiles.com/files/1037160/gedamowikusoduxupo.pdf
- https://site-1036852.mozfiles.com/files/1036852/xezobigiliga.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1037172.mozfiles.com
- site-1037189.mozfiles.com
- site-1036711.mozfiles.com
- site-1037125.mozfiles.com
- site-1036649.mozfiles.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1037160.mozfiles.com
- site-1036852.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report