SUSPICIOUS — tusokaf.pdf
SUSPICIOUS — tusokaf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
47acae119bb404ed1077459949706f351147c131c2219000dcec315d20dcdf1c - SHA-1:
8abe3b22eca06f179d6e85b84047a7c31b0f58e0 - MD5:
efbbd697e6101c68ef5d49ce7f3e6881 - ssdeep:
768:/gGzpDRjaYR50pj0vGE6zCPS+kpA4xDYVFqg0NDTgmJS5H/0uz:IGFNjRHjgCi/DwqggDJS5H/0uz - TLSH:
T195319DF350ABED4C3A829B13ADFA1958608587887167E3744CCC7A3DC9786FCAE50650 - Submitted as: tusokaf.pdf
- File type: pdf · Size: 43030 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://files.langsidechurch.org/uploads/1/3/2/3/132303061/3cc50cd3e1.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=leadership+skills+for+project+managers+pdf, https://site-1036722.mozfiles.com/files/1036722/vijudi.pdf, https://site-1036823.mozfiles.com/files/1036823/muzamotivunavozagimozaf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=leadership+skills+for+project+managers+pdf
- https://site-1036722.mozfiles.com/files/1036722/vijudi.pdf
- https://site-1036823.mozfiles.com/files/1036823/muzamotivunavozagimozaf.pdf
- https://site-1037054.mozfiles.com/files/1037054/gufevunivofogilisokegowup.pdf
- https://site-1036812.mozfiles.com/files/1036812/74774665884.pdf
- https://site-1036711.mozfiles.com/files/1036711/nemumivaxe.pdf
- http://files.holyangelsnj.org/uploads/1/3/0/9/130969980/6a2bd79e6506.pdf
- http://files.adglresources.com/uploads/1/3/0/9/130969481/wibupivogitatoguwam.pdf
- http://files.langsidechurch.org/uploads/1/3/2/3/132303061/3cc50cd3e1.pdf
- https://uploads.strikinglycdn.com/files/dd3c2ecb-202d-4957-adb1-14fa3f1f3064/vudubapapugikatawopog.pdf
- https://uploads.strikinglycdn.com/files/cf7e4915-56b2-4dfa-957b-0f59c51f3086/zupijufolapikulaji.pdf
- https://uploads.strikinglycdn.com/files/fa10cae5-32dc-47f1-9574-e6e1a36a8286/92969143953.pdf
- http://files.stgeorgestbishoyvisalia.com/uploads/1/3/1/4/131407549/rufonimexabe.pdf
- http://files.perturbmusic.studio/uploads/1/3/2/6/132681887/winozow-xivubafidu-juxefubupidi-fuxamosedigoxu.pdf
- http://talejon.australiasmedium.com/uploads/1/3/1/4/131407227/nurixuxobo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1036722.mozfiles.com
- site-1036823.mozfiles.com
- site-1037054.mozfiles.com
- site-1036812.mozfiles.com
- site-1036711.mozfiles.com
- files.holyangelsnj.org
- files.adglresources.com
- files.langsidechurch.org
- uploads.strikinglycdn.com
- files.stgeorgestbishoyvisalia.com
- talejon.australiasmedium.com
- www.w3.org
- purl.org
- ns.adobe.com
- files.perturbmusic.studio
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report