SUSPICIOUS — main_hoon_na_torrent.pdf
SUSPICIOUS — main_hoon_na_torrent.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4c357f81d96494bbd132cf14a2a9e518a202463b79b4ed1153a6313391d87e2b - SHA-1:
505a88e511ef5f549b9bd9381af32e51dd87ddb3 - MD5:
9918bc775dc8cfd147deee276c1fd650 - ssdeep:
768:8gGzpDmp2BI6gPqgXlQLZYeLosX9E4DSQxWaM5Q6bHjuKBRiSFfRlKTPWY:ZGFypn4CzjuKBRiSFfRlKTPWY - TLSH:
T1C6328DFB1497EC4CBE8B9B03BCAB256A1189C349A236A710448C672DD1BC5BD7F10B11 - Submitted as: main_hoon_na_torrent.pdf
- File type: pdf · Size: 44983 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/2d7c8a28-12af-4790-9216-77ae83f2ed46/dizetunewonejadetusu.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=main+hoon+na+torrent, https://pejopazuzaguwoz.weebly.com/uploads/1/3/2/8/132815183/vukajuxeravetiwaze.pdf, https://molisemopum.weebly.com/uploads/1/3/1/4/131437834/54e5b6cb416.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=main+hoon+na+torrent
- https://pejopazuzaguwoz.weebly.com/uploads/1/3/2/8/132815183/vukajuxeravetiwaze.pdf
- https://molisemopum.weebly.com/uploads/1/3/1/4/131437834/54e5b6cb416.pdf
- https://kurikezexiwu.weebly.com/uploads/1/3/0/7/130775092/1144695.pdf
- https://jopalezaleloloj.weebly.com/uploads/1/3/1/3/131380469/833baccd.pdf
- https://nikokabiliru.weebly.com/uploads/1/3/1/4/131409463/kisewoviretawu.pdf
- https://cdn.shopify.com/s/files/1/0464/7380/5982/files/durusalulusivuxulokes.pdf
- https://cdn.shopify.com/s/files/1/0440/3298/3190/files/63396727794.pdf
- https://cdn.shopify.com/s/files/1/0432/4933/6483/files/64221656806.pdf
- https://cdn.shopify.com/s/files/1/0428/8249/8716/files/75512403252.pdf
- https://cdn.shopify.com/s/files/1/0500/2743/0059/files/history_of_assemblies_of_god_ghana.pdf
- https://cdn.shopify.com/s/files/1/0482/4488/3608/files/xatabewikafedituri.pdf
- https://cdn.shopify.com/s/files/1/0432/5592/2852/files/runobe.pdf
- https://cdn.shopify.com/s/files/1/0497/9189/3666/files/38064917432.pdf
- https://cdn.shopify.com/s/files/1/0484/7203/1382/files/chapter_6_cumulative_review_answers_algebra_2.pdf
- https://cdn.shopify.com/s/files/1/0266/9510/6741/files/73485452218.pdf
- https://cdn.shopify.com/s/files/1/0438/3594/9218/files/juvulizebuwemidikogowezim.pdf
- https://cdn.shopify.com/s/files/1/0438/3768/5920/files/64871183353.pdf
- https://cdn.shopify.com/s/files/1/0497/2409/6669/files/bullet_for_my_valentine_songs_ranked.pdf
- https://uploads.strikinglycdn.com/files/25b97ccd-7693-44b5-8f74-5d9ef9a86045/getijuruvawulej.pdf
- https://uploads.strikinglycdn.com/files/92a894ac-0567-4948-b4da-3efbe7adde9f/18895997197.pdf
- https://uploads.strikinglycdn.com/files/d6ed0925-4bca-441e-b284-1a2bffd8d9c7/33481579064.pdf
- https://uploads.strikinglycdn.com/files/2d7c8a28-12af-4790-9216-77ae83f2ed46/dizetunewonejadetusu.pdf
- https://uploads.strikinglycdn.com/files/8da8d933-1e6e-4b38-a94e-91e6083c4d5e/53944825580.pdf
- https://uploads.strikinglycdn.com/files/18d91228-6c1e-4685-b462-ddfba3439b71/gigutulisoje.pdf
Embedded domains
- ggtraff.ru
- pejopazuzaguwoz.weebly.com
- molisemopum.weebly.com
- kurikezexiwu.weebly.com
- jopalezaleloloj.weebly.com
- nikokabiliru.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report