SUSPICIOUS — notice_me_senpai_notice_me.pdf
SUSPICIOUS — notice_me_senpai_notice_me.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3caeaca00c50fdf52118ec1b0cbb6307bd240208cc8fce59716a26b517d21a41 - SHA-1:
8857d9bfa55ef0cfb82573c63d8af6a57993d47d - MD5:
bd254c01f82d318b9cd23034be3b7d66 - ssdeep:
768:wgGzpDfe9Ptvv9czc4plGUSOg4kmH0Dmq5cF1iV3tjL+OowNyAZlT:dGF7eKzcKrrK2cBteOLZlT - TLSH:
T114338DF35067EC8C7B8A9B13ADBB1459649EDB886132DB504488772CC4BC6FD3E10A60 - Submitted as: notice_me_senpai_notice_me.pdf
- File type: pdf · Size: 50778 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://taxajadotediru.weebly.com/uploads/1/3/0/8/130873824/zutabolom-neritevi-wapatokilab-nilelebatojo.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=notice+me+senpai+notice+me, https://digafixi.weebly.com/uploads/1/3/0/7/130776371/a0d7209b96ca.pdf, https://noxepelobisuse.weebly.com/uploads/1/3/1/8/131871648/9582547f98b.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=notice+me+senpai+notice+me
- https://digafixi.weebly.com/uploads/1/3/0/7/130776371/a0d7209b96ca.pdf
- https://noxepelobisuse.weebly.com/uploads/1/3/1/8/131871648/9582547f98b.pdf
- https://taxajadotediru.weebly.com/uploads/1/3/0/8/130873824/zutabolom-neritevi-wapatokilab-nilelebatojo.pdf
- https://cdn.shopify.com/s/files/1/0493/7252/8799/files/57441832700.pdf
- https://cdn.shopify.com/s/files/1/0434/8932/9312/files/renaissance_book_quiz_answers.pdf
- https://cdn.shopify.com/s/files/1/0439/5030/9531/files/que_nuevos_productos_sugiere_para_papalote.pdf
- https://cdn.shopify.com/s/files/1/0501/0613/8787/files/product_development_process.pdf
- https://s3.amazonaws.com/bezutu/65265296386.pdf
- https://s3.amazonaws.com/xuzed/advanced_data_structures_and_algorithms_notes_for_m._tech.pdf
- https://s3.amazonaws.com/zategafozasiru/segejizigago.pdf
- https://s3.amazonaws.com/zurovajij/13837231651.pdf
- https://s3.amazonaws.com/memul/farepijegemo.pdf
- https://cdn-cms.f-static.net/uploads/4366007/normal_5f87c5a5ad3c4.pdf
- https://cdn-cms.f-static.net/uploads/4372955/normal_5f899f74d32a9.pdf
- https://cdn-cms.f-static.net/uploads/4369771/normal_5f8cc16ae5500.pdf
- https://uploads.strikinglycdn.com/files/1cb8f72f-c1c9-4409-8bcf-92bebb9b83c8/daemon_tools_full_mega_64_bits.pdf
- https://uploads.strikinglycdn.com/files/0bf6ae85-82f2-4b7b-aa97-098291408237/kuzenijunotapepebirimar.pdf
- https://uploads.strikinglycdn.com/files/dab8266e-377a-4d77-9721-21f0838a5551/vexawewenuzejebozor.pdf
- https://uploads.strikinglycdn.com/files/62538af8-e876-41e6-95f8-d7b65889bb8c/60813958163.pdf
- https://uploads.strikinglycdn.com/files/be198b62-96be-4aaa-ba31-f5c3daeccd00/77972111267.pdf
- https://cdn-cms.f-static.net/uploads/4385217/normal_5f922f05020e8.pdf
- https://cdn-cms.f-static.net/uploads/4374177/normal_5f918618ea403.pdf
- https://cdn-cms.f-static.net/uploads/4383929/normal_5f8cae7a71981.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- digafixi.weebly.com
- noxepelobisuse.weebly.com
- taxajadotediru.weebly.com
- cdn.shopify.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report