SUSPICIOUS — pajokoruzerilu.pdf
SUSPICIOUS — pajokoruzerilu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
315294d6344a42b88d3b7cc280834363322ddcc50ee4e5c9a19745103dd5bffa - SHA-1:
316fdb233f4e600fe9b859b8b750127350590c1e - MD5:
71f236d483370389dbf4f366810ab96f - ssdeep:
1536:XGFTePxTtuFNka/92LP4BmxqDLfDQlPx3jg:2FTeZM7LM0mgDzD0c - TLSH:
T1AA35BEF355A7EC4C7ACBA7436CEA30592449C789A232DB8005C8763DC6BC6BD7E20911 - Submitted as: pajokoruzerilu.pdf
- File type: pdf · Size: 58513 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/f462db10-7ca7-400d-9300-5e7257d89125/21018096663.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=nfs%20most%20wanted%20android%201, https://uploads.strikinglycdn.com/files/f462db10-7ca7-400d-9300-5e7257d89125/21018096663.pdf, https://uploads.strikinglycdn.com/files/e8c0a702-1bd7-475c-8ef9-4c990e88e2f9/58613128143.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=nfs%20most%20wanted%20android%201
- https://uploads.strikinglycdn.com/files/f462db10-7ca7-400d-9300-5e7257d89125/21018096663.pdf
- https://uploads.strikinglycdn.com/files/e8c0a702-1bd7-475c-8ef9-4c990e88e2f9/58613128143.pdf
- https://uploads.strikinglycdn.com/files/becc6b9f-1394-41cc-989b-4c7a12c7a9d5/33479996626.pdf
- https://uploads.strikinglycdn.com/files/f07de53e-a5d2-49aa-8441-8589b21d4caa/58664265336.pdf
- https://uploads.strikinglycdn.com/files/f42359a3-e055-49c8-a08d-aa4fd7163c5a/69828224318.pdf
- https://cdn.shopify.com/s/files/1/0436/1686/2371/files/lugatijukediwizupefoz.pdf
- https://cdn.shopify.com/s/files/1/0434/4519/0821/files/strand_theatre_nyc.pdf
- https://cdn.shopify.com/s/files/1/0502/4595/9845/files/tazivomasitegepepapame.pdf
- https://cdn.shopify.com/s/files/1/0484/2831/8877/files/28156837750.pdf
- https://cdn.shopify.com/s/files/1/0496/1838/7107/files/kenmore_70_series_gas_dryer_parts_diagram.pdf
- https://lotagixowila.weebly.com/uploads/1/3/1/1/131164100/nukaxiweroteme_zotujaxotejadu_rekajaka.pdf
- https://naxesitigas.weebly.com/uploads/1/3/0/7/130740165/877802.pdf
- https://pejapuvurexoku.weebly.com/uploads/1/3/1/6/131636728/misovunopevowiz.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/wotareropajewub.pdf
- https://dirigesibujov.weebly.com/uploads/1/3/0/9/130969991/rujanusowijakefifa.pdf
- https://site-1041074.mozfiles.com/files/1041074/kaxevoxapo.pdf
- https://site-1044312.mozfiles.com/files/1044312/lenovo_tablet_android_10_1.pdf
- https://site-1040975.mozfiles.com/files/1040975/gijivuvezazivo.pdf
- https://uploads.strikinglycdn.com/files/50e4b9df-33a6-4608-9693-74a692f61608/41128356907.pdf
- https://uploads.strikinglycdn.com/files/9c11ba73-e57c-4f9d-bd97-4335b08d1d0d/76986964849.pdf
- https://uploads.strikinglycdn.com/files/c1491a23-9515-4593-b433-90db2b61a07f/wulijisebijajitexi.pdf
- https://cdn.shopify.com/s/files/1/0493/0250/3583/files/kusiwovoxodatuzezerono.pdf
- https://cdn.shopify.com/s/files/1/0493/7210/2822/files/98508251845.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- lotagixowila.weebly.com
- naxesitigas.weebly.com
- pejapuvurexoku.weebly.com
- gimejexoxixaza.weebly.com
- dirigesibujov.weebly.com
- site-1041074.mozfiles.com
- site-1044312.mozfiles.com
- site-1040975.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report