SUSPICIOUS — lifivu.pdf
SUSPICIOUS — lifivu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4d9ac313fca45987e8691f760ccd9ae446b42e9aea6ffb7e48a73c8919d0582c - SHA-1:
4ad4efbad38867541db5aef7b0221a5060c4ffe1 - MD5:
3ddd6bfa47506001004be76ed7499eb2 - ssdeep:
768:/gGzpD6EpdCYidEEo7fuqRVewQpuY9EDkfWWmcApfumic8hqzlDELuVuB2mN:IGFlpoQTbVZQkYNfhmdpfumWhq6ymN - TLSH:
T1AE329DF3409BDC8CB9869B43ADAA15562045D7886037E76054CC7A3DC8BC6FEBE20960 - Submitted as: lifivu.pdf
- File type: pdf · Size: 44286 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/3bc72377-95d2-47de-8012-b07e0a2b83e6/95179280018.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=revenge+of+the+dreamers+2+download+zip, https://site-1038790.mozfiles.com/files/1038790/21589277532.pdf, https://site-1042677.mozfiles.com/files/1042677/xogadawagunuzakapebesigu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=revenge+of+the+dreamers+2+download+zip
- https://site-1038790.mozfiles.com/files/1038790/21589277532.pdf
- https://site-1042677.mozfiles.com/files/1042677/xogadawagunuzakapebesigu.pdf
- https://site-1036962.mozfiles.com/files/1036962/dazaveponedojipesuradudus.pdf
- https://site-1037211.mozfiles.com/files/1037211/36760367953.pdf
- http://vurumux.dukes-designs.com/uploads/1/3/0/8/130814070/1925dce05589.pdf
- http://riren.joelwhitney.net/uploads/1/3/0/7/130739873/bubisilofu.pdf
- http://xorixu.wonderimages.org/uploads/1/3/2/8/132814170/890c1028e.pdf
- https://uploads.strikinglycdn.com/files/3bc72377-95d2-47de-8012-b07e0a2b83e6/95179280018.pdf
- https://uploads.strikinglycdn.com/files/ea92b45d-f801-4040-a252-035052f16c88/gafejedijamabuzujogeketod.pdf
- https://uploads.strikinglycdn.com/files/ae0e363d-3232-4515-8422-6cd0ed8b201e/24152986159.pdf
- https://uploads.strikinglycdn.com/files/f9206b88-15ce-4f50-955a-6aaed2efdd09/84633668274.pdf
- https://uploads.strikinglycdn.com/files/735e3f3f-568c-42ea-8f39-b9fe87690b6c/nidorikonufifakafobe.pdf
- https://uploads.strikinglycdn.com/files/36c6b669-629a-47f9-8afe-c96d46ce8abb/vofelunozulifasikifixeb.pdf
- https://uploads.strikinglycdn.com/files/ba63d206-42da-406d-8239-0671394a975d/83635180084.pdf
- https://uploads.strikinglycdn.com/files/2ddb35f3-657a-4e3e-9af8-89be7c9a069b/20284186956.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1038790.mozfiles.com
- site-1042677.mozfiles.com
- site-1036962.mozfiles.com
- site-1037211.mozfiles.com
- vurumux.dukes-designs.com
- riren.joelwhitney.net
- xorixu.wonderimages.org
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report