SUSPICIOUS — kojiram.pdf
SUSPICIOUS — kojiram.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
431c62e4f0b7fb459c93824c0c908a53cf2e370b1aa9910c2c98de3beeb573cc - SHA-1:
235cf58bdbbed474ebea251cc99a73834aaa5c98 - MD5:
8ff241385b83112889296f1a35edf3ce - ssdeep:
768:DgGzpDTpdWKwZXVjefKhdXGaBwkYEXd9/iW+EMfSn8hF7kPfNhhQvXds:8GFPpdXwpnTYEXdD+EMfSn8v0kXds - TLSH:
T1E5319EF35597ED4C7A8BAB03AAA721696189D78C3132E36054CC372DC4BC6BD6E10870 - Submitted as: kojiram.pdf
- File type: pdf · Size: 42480 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/fd4b52e4-d703-448c-811e-a600714c59c2/vojesuterejege.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=hogwarts%20an%20incomplete%20and%20unreliable%20guide%20hard%20copy, https://uploads.strikinglycdn.com/files/4385f213-87e4-4341-bfc6-45cc70022e5a/76303628674.pdf, https://uploads.strikinglycdn.com/files/2547acbe-5406-4e8e-81ac-382efa982d7b/ruwanawinagopiwim.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=hogwarts%20an%20incomplete%20and%20unreliable%20guide%20hard%20copy
- https://uploads.strikinglycdn.com/files/4385f213-87e4-4341-bfc6-45cc70022e5a/76303628674.pdf
- https://uploads.strikinglycdn.com/files/2547acbe-5406-4e8e-81ac-382efa982d7b/ruwanawinagopiwim.pdf
- https://uploads.strikinglycdn.com/files/16819c73-c279-4436-bb16-36d6711fed81/gifudi.pdf
- https://site-1042502.mozfiles.com/files/1042502/tufelesejudazibopakovuli.pdf
- https://uploads.strikinglycdn.com/files/fd4b52e4-d703-448c-811e-a600714c59c2/vojesuterejege.pdf
- https://uploads.strikinglycdn.com/files/6a4953a1-59ff-4fcf-bb6a-e14dd449999d/79810346163.pdf
- https://uploads.strikinglycdn.com/files/256b4aab-c3ce-4179-8e2a-7a3470ef9cb5/fufajapivupe.pdf
- https://uploads.strikinglycdn.com/files/42206c82-b714-4aaf-9482-4b02cbf654cd/72036434349.pdf
- https://uploads.strikinglycdn.com/files/eac6077d-e1b1-45be-8921-e10e97ae26de/sekasesaran.pdf
- https://uploads.strikinglycdn.com/files/29ed3d93-eb51-4fb3-bb66-116e6d87245f/dajimomalolonen.pdf
- https://uploads.strikinglycdn.com/files/c770c569-78af-4bcf-ab17-570acbfc6a48/58283509459.pdf
- https://uploads.strikinglycdn.com/files/55e213a4-f9dd-41fd-89aa-5c72578051a8/fijajukerovafeba.pdf
- https://uploads.strikinglycdn.com/files/9bc96c23-05ad-46d8-82ac-f05fdfcd4f00/kufijikerogunev.pdf
- https://cdn-cms.f-static.net/uploads/4366357/normal_5f872faca1893.pdf
- https://cdn-cms.f-static.net/uploads/4365659/normal_5f8715cc9f31f.pdf
- https://sepikupi.weebly.com/uploads/1/3/0/7/130738949/rajobogupur_fupajaxaf_nodiwugev_bufilexisonovum.pdf
- https://walijogopabo.weebly.com/uploads/1/3/0/7/130776167/jesudasa_bidez_misunesamaki_takixezeve.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1042502.mozfiles.com
- cdn-cms.f-static.net
- sepikupi.weebly.com
- walijogopabo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report