SUSPICIOUS — runetasonutimubaf.pdf
SUSPICIOUS — runetasonutimubaf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3cc50d3b380f7ecf5734a213baf2e535accbabbf3307d01fb5c6969d1e881c93 - SHA-1:
d4eb777f742a0726b840729272b098ab716aca40 - MD5:
9dfeb4468a3261f07dc21f3266012ed0 - ssdeep:
768:jgGzpDapX+4pLccLkB+N/zUpQpsa6DBycsRrMKhsiF+ErbhGsSvjguGo/Ub/:cGFWpXd5TkYN4p/ycspMss8JhuVsb/ - TLSH:
T148329EF351E3EC4C7B8B6B13AEAB1169518AC34C61369750488C3B2DC47CABE7E40A41 - Submitted as: runetasonutimubaf.pdf
- File type: pdf · Size: 47135 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://jeponiruwapin.weebly.com/uploads/1/3/0/7/130776483/ludawaxed_ritazi_pixoxir_visutan.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=the+child+by+tiger, https://uploads.strikinglycdn.com/files/733bcda2-f0ab-484d-ae0c-c60a8595da2a/goxunetideferufadufome.pdf, https://uploads.strikinglycdn.com/files/a459ab26-4ce0-42b4-8dd6-5b1817bdc86e/nugejuberafazeponolizuwo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=the+child+by+tiger
- https://uploads.strikinglycdn.com/files/733bcda2-f0ab-484d-ae0c-c60a8595da2a/goxunetideferufadufome.pdf
- https://uploads.strikinglycdn.com/files/a459ab26-4ce0-42b4-8dd6-5b1817bdc86e/nugejuberafazeponolizuwo.pdf
- https://uploads.strikinglycdn.com/files/4a7977d8-a69f-4f03-a4e2-f9c6d4f3fc32/tibitag.pdf
- https://uploads.strikinglycdn.com/files/510e62a3-e3e3-4d6e-ba1e-2107b97db2f6/lutovuxunuxenolujex.pdf
- https://jeponiruwapin.weebly.com/uploads/1/3/0/7/130776483/ludawaxed_ritazi_pixoxir_visutan.pdf
- https://mixorone.weebly.com/uploads/1/3/1/4/131438240/1ee4b70a4.pdf
- https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/lurexur.pdf
- https://suganolorifumu.weebly.com/uploads/1/3/0/8/130814011/ripike.pdf
- https://tiwilofudux.weebly.com/uploads/1/3/1/6/131606348/4869460.pdf
- https://uploads.strikinglycdn.com/files/77e7b9b4-b1c3-4d0a-8138-02ef1acf7dda/84187485096.pdf
- https://uploads.strikinglycdn.com/files/14d9dd4f-3ff6-4440-b759-f0f58a126a32/neverwinter_scourge_warlock_guide.pdf
- https://uploads.strikinglycdn.com/files/71af641b-6dc2-43e8-85d1-3b1b2d550e31/93469699360.pdf
- https://uploads.strikinglycdn.com/files/43469063-9d4e-4cd1-8ecc-9674c934e57e/xugiwusoxavugoreteg.pdf
- https://uploads.strikinglycdn.com/files/bee25fa6-b31c-4119-a72a-5a136a1227ed/course_de_dure_cycle_3.pdf
- https://uploads.strikinglycdn.com/files/8c87f2f6-8f20-45dd-8106-4c21d563eee9/putelakugigiridobena.pdf
- https://uploads.strikinglycdn.com/files/4caa0bab-b4e5-44f3-94dc-33f3a254ee23/fasibivuxe.pdf
- https://uploads.strikinglycdn.com/files/a36748b6-b88d-4bb9-a2a0-d941ac7ca3e3/scooby_doo_and_the_spooky_swamp_ds.pdf
- https://uploads.strikinglycdn.com/files/fcd33de2-dd84-4ab8-91c9-1b0edb382f6d/25447693624.pdf
- https://uploads.strikinglycdn.com/files/26e86d14-058d-48db-b55c-d257a3b79bd4/xokurafitozusamukejinuvu.pdf
- https://uploads.strikinglycdn.com/files/bbb39a85-5e6c-4fc6-acbf-76b48d80871d/18842427479.pdf
- https://uploads.strikinglycdn.com/files/df2903cd-ea95-4a18-bfd6-d6a2f1470b0e/1980245165.pdf
- https://cdn-cms.f-static.net/uploads/4369671/normal_5f8b9b8373053.pdf
- https://cdn-cms.f-static.net/uploads/4369930/normal_5f88dcf839410.pdf
- https://cdn-cms.f-static.net/uploads/4366989/normal_5f874e06b2b5e.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- jeponiruwapin.weebly.com
- mixorone.weebly.com
- tivakoxidedopa.weebly.com
- suganolorifumu.weebly.com
- tiwilofudux.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report