SUSPICIOUS — jelajafozubituxejukud.pdf
SUSPICIOUS — jelajafozubituxejukud.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3b88785d998df4ae7ee2882274c48a333c4d1c5dbf2fa3854843c4d566641b1b - SHA-1:
a69e70e9fed49809f1d099e4b2d0a27c54e90980 - MD5:
9085dce117e23a3ce7c36d6d6665cc31 - ssdeep:
768:fgGzpDkB1/luitpWX+gzo36BlK9DD7odgN1c7byMj/XoK2aX5VIPLb+V:oGFIBCW9abBcBnpN52AK2aX5cb+V - TLSH:
T127338EF35097ED9C7A87EB036DEA244C5189C38C6172A75094887B7DC57C3BD6E10A60 - Submitted as: jelajafozubituxejukud.pdf
- File type: pdf · Size: 48271 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/96248765-31ce-4523-a89f-17ec464616f0/fagokapexegosapifiwu.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=biochemistry+satyanarayana+book+pdf+download, https://uploads.strikinglycdn.com/files/96248765-31ce-4523-a89f-17ec464616f0/fagokapexegosapifiwu.pdf, https://uploads.strikinglycdn.com/files/cf3e66a6-b02b-4ca4-b276-22ccd317f5ce/jelapesepin.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=biochemistry+satyanarayana+book+pdf+download
- https://uploads.strikinglycdn.com/files/96248765-31ce-4523-a89f-17ec464616f0/fagokapexegosapifiwu.pdf
- https://uploads.strikinglycdn.com/files/cf3e66a6-b02b-4ca4-b276-22ccd317f5ce/jelapesepin.pdf
- https://uploads.strikinglycdn.com/files/39934d59-fec4-49eb-8758-c1608f5d5a49/48279595313.pdf
- https://uploads.strikinglycdn.com/files/ff9d5d80-7c3b-405a-9e3d-a1b1c6daa31a/lirupabujunof.pdf
- https://uploads.strikinglycdn.com/files/35d89bfd-60cb-4f04-8d0b-3f23e432e71e/wegaxunivedawejekus.pdf
- https://site-1037848.mozfiles.com/files/1037848/17014289644.pdf
- https://site-1036637.mozfiles.com/files/1036637/dojiregivul.pdf
- https://site-1036972.mozfiles.com/files/1036972/poguzobenadev.pdf
- https://site-1037191.mozfiles.com/files/1037191/20964159407.pdf
- https://site-1036874.mozfiles.com/files/1036874/96777445440.pdf
- https://site-1036713.mozfiles.com/files/1036713/sifudekutijerakeviluvu.pdf
- https://site-1037160.mozfiles.com/files/1037160/lujawudomagonivuzajebof.pdf
- https://uploads.strikinglycdn.com/files/3ce42680-2d82-4e72-b1de-e8619c461fde/mefojomupazubewadow.pdf
- https://uploads.strikinglycdn.com/files/c0800dbc-2235-4e0a-82a5-29ee07540001/mojowanune.pdf
- https://uploads.strikinglycdn.com/files/9bc59a68-1923-4eb9-bb83-d9092909e535/biwipafot.pdf
- https://uploads.strikinglycdn.com/files/cad0e3c5-e189-4822-b726-c708a320054a/64686086325.pdf
- https://uploads.strikinglycdn.com/files/b9239218-7045-4540-b5dd-17ef00c3e956/46780553084.pdf
- http://cinurl.com/13tbq1
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1037848.mozfiles.com
- site-1036637.mozfiles.com
- site-1036972.mozfiles.com
- site-1037191.mozfiles.com
- site-1036874.mozfiles.com
- site-1036713.mozfiles.com
- site-1037160.mozfiles.com
- cinurl.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report