SUSPICIOUS — luripusiz.pdf
SUSPICIOUS — luripusiz.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1bb3b39a42599edf4215ca07b942e6008876030805d7cd259125808175307ab8 - SHA-1:
1421c26664dedc36f10084eea2576322e24f5ecc - MD5:
64a59b32da90a4c8fbd62b353d0304e3 - ssdeep:
1536:MGFMG8En6rhi+y5UwDHy3nm63SA/8l4s2MgG6LPxh/jIaAq:pFMGn6roKV3nm2b/M2MgG6LPxREW - TLSH:
T17438D0F350B7EE8C769F7F036AAB15A8654AC2897037E3A00544A7BDC8785EC2F01951 - Submitted as: luripusiz.pdf
- File type: pdf · Size: 76635 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://files.tracystreks.com/uploads/1/3/0/7/130775615/8722e.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=aggiornamento+autoradio+android+6.0, https://uploads.strikinglycdn.com/files/01411211-4dbd-423c-8237-7fde7b82c88e/popuvusarasopaj.pdf, https://uploads.strikinglycdn.com/files/fb90cd74-5955-4621-aaf1-01c9bf6390e6/xexibabitedulufozuzawaban.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=aggiornamento+autoradio+android+6.0
- https://uploads.strikinglycdn.com/files/01411211-4dbd-423c-8237-7fde7b82c88e/popuvusarasopaj.pdf
- https://uploads.strikinglycdn.com/files/fb90cd74-5955-4621-aaf1-01c9bf6390e6/xexibabitedulufozuzawaban.pdf
- https://uploads.strikinglycdn.com/files/869200ab-78d7-4088-b06e-82654b044a63/135386196.pdf
- https://uploads.strikinglycdn.com/files/088ece37-3711-4d7c-bc8d-dacfc0f98ace/78132338668.pdf
- https://uploads.strikinglycdn.com/files/83e9175a-de07-4eee-acb7-db840b4364d9/riwibuzuburizalomojon.pdf
- http://files.healthgeography.org/uploads/1/3/0/7/130776158/3254967.pdf
- http://files.tracystreks.com/uploads/1/3/0/7/130775615/8722e.pdf
- http://files.dragondistillery.com/uploads/1/3/1/4/131483002/vilexu.pdf
- http://masok.atthehealersnook.com/uploads/1/3/1/3/131398285/judakoxudimoxesonem.pdf
- http://files.positivesportcoaching.org/uploads/1/3/0/9/130969678/3145967.pdf
- http://files.sidemountainspecialtyfoods.com/uploads/1/3/1/4/131406520/popenigezalagos.pdf
- http://files.pmlaboratory.com/uploads/1/3/1/4/131438353/pevuvukeko.pdf
- https://uploads.strikinglycdn.com/files/d9f4efb6-b35d-4283-a401-f0f9abc74ad3/xubawimutiweje.pdf
- https://uploads.strikinglycdn.com/files/0aebea85-7874-4202-b117-b50feddc998a/jifewu.pdf
- https://uploads.strikinglycdn.com/files/126517fd-9b62-40b9-a2e0-aac7e67c428e/vurotodu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- files.healthgeography.org
- files.tracystreks.com
- files.dragondistillery.com
- masok.atthehealersnook.com
- files.positivesportcoaching.org
- files.sidemountainspecialtyfoods.com
- files.pmlaboratory.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report