SUSPICIOUS — the_juicing_bible_download.pdf
SUSPICIOUS — the_juicing_bible_download.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
26c3442550113a1836358fc13b0a24c01daca04f140e9fc9c31237e24852128a - SHA-1:
9b6769056633698082b69eac5c463b1b9d713a4b - MD5:
35c52184c27d61227a0c27bfe5b066d4 - ssdeep:
1536:YGFepFcQlTjFlyW99Bncsa5MilEd6++DbJ:1FepFcATjZ99SjWei6++B - TLSH:
T1E234CFF745EBECCC7A8B9B13BEAA2455214EC7492232976005CCB72CC4BC27D6E24552 - Submitted as: the_juicing_bible_download.pdf
- File type: pdf · Size: 56206 bytes
- Verdict: suspicious (58/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/b3452c45-fa54-4fab-a894-cd163fb80a17/nonopuza.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=the+juicing+bible+pdf+download, https://uploads.strikinglycdn.com/files/b3452c45-fa54-4fab-a894-cd163fb80a17/nonopuza.pdf, https://uploads.strikinglycdn.com/files/fff5a552-d224-401c-bd75-951aac23db94/jowosuragediraxasojukug.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=the+juicing+bible+pdf+download
- https://uploads.strikinglycdn.com/files/b3452c45-fa54-4fab-a894-cd163fb80a17/nonopuza.pdf
- https://uploads.strikinglycdn.com/files/fff5a552-d224-401c-bd75-951aac23db94/jowosuragediraxasojukug.pdf
- https://uploads.strikinglycdn.com/files/1c6f1d8b-632d-4f06-945b-bdcf4462cc03/monuwozivexijalasufopil.pdf
- https://uploads.strikinglycdn.com/files/94e1bdb4-6725-4ea7-bf83-84e7ae52cb26/40033169681.pdf
- https://cdn-cms.f-static.net/uploads/4366344/normal_5f870dab5268c.pdf
- https://cdn.shopify.com/s/files/1/0484/2455/0552/files/81269641854.pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/threatening_with_a_bladed_article_sentencing_guidelines.pdf
- https://cdn.shopify.com/s/files/1/0436/6991/3753/files/psiphon_apk_new_version.pdf
- https://cdn.shopify.com/s/files/1/0437/6258/1658/files/online_volunteer_opportunities_for_college_students.pdf
- https://cdn.shopify.com/s/files/1/0502/7853/1255/files/improper_to_mixed_number_fractions_worksheet.pdf
- https://uploads.strikinglycdn.com/files/33008df4-581a-425f-895b-8c858539800d/62813185006.pdf
- https://uploads.strikinglycdn.com/files/6a336f4d-1976-4f22-9461-c75f85ee8ce9/fabixokuz.pdf
- https://givifajilodox.weebly.com/uploads/1/3/0/8/130874655/lugixomo_dilufudetinevid_vibupipiz_bogizolu.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/2a5b38eef3430.pdf
- https://uploads.strikinglycdn.com/files/3b50b88a-3280-4dac-9ea8-eeaaeb9a3edc/rifolukobozez.pdf
- https://uploads.strikinglycdn.com/files/6f411eb6-9e44-401a-9ae8-a5b8a63e5f41/jalewozesimeforod.pdf
- https://uploads.strikinglycdn.com/files/ea33a98a-0ba1-441b-babe-c8b7ac5915b0/31345274077.pdf
- https://uploads.strikinglycdn.com/files/38827332-13cf-4d25-bcb2-5607875ea82f/tugiwexikuxitesazamatiw.pdf
- https://uploads.strikinglycdn.com/files/08f2df63-4096-4013-a6bb-05dbca0f4aae/23445923526.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- givifajilodox.weebly.com
- guwomenod.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report