SUSPICIOUS — vunosemaxevubejenuj.pdf
SUSPICIOUS — vunosemaxevubejenuj.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5a221c4a44d47f8f97558145cbffafabd1adbce487f84cfe4d0a7226ac0ff720 - SHA-1:
1fd5a4ccb39e50d3ae48928ac08b0e8d029707ab - MD5:
b49010a0f7e5563a7ebb6806308cd066 - ssdeep:
768:EgGzpDcANwB0h15Vn4XXBuaAALZI+fLtBkZtrA2yAItivzljYREZc:xGF45XOqZI+TtBOtAAIUvzyREZc - TLSH:
T1C233BFF3518BEC8C7F969B07A9B601296148C68D3272A7A05DCCB73CC0BC6BD6D14961 - Submitted as: vunosemaxevubejenuj.pdf
- File type: pdf · Size: 48944 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/4bdd88b3-5b88-43cd-b9fb-6f8202d8d743/77784884501.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=barking+up+the+wrong+tree+book+pdf, https://cdn.shopify.com/s/files/1/0480/8510/6852/files/plants_vs_zombies_heroes_mod_apk_unlimited_sun.pdf, https://cdn.shopify.com/s/files/1/0485/9330/5760/files/elizabeth_smart_book.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=barking+up+the+wrong+tree+book+pdf
- https://cdn.shopify.com/s/files/1/0480/8510/6852/files/plants_vs_zombies_heroes_mod_apk_unlimited_sun.pdf
- https://cdn.shopify.com/s/files/1/0485/9330/5760/files/elizabeth_smart_book.pdf
- https://cdn.shopify.com/s/files/1/0497/2501/4173/files/zedazugixoneli.pdf
- https://cdn.shopify.com/s/files/1/0499/1690/3585/files/vamib.pdf
- https://cdn.shopify.com/s/files/1/0430/1049/0519/files/87937271702.pdf
- https://uploads.strikinglycdn.com/files/4bdd88b3-5b88-43cd-b9fb-6f8202d8d743/77784884501.pdf
- https://uploads.strikinglycdn.com/files/6c9637b8-1f03-4ef6-b40b-06f43247cfc7/wededivireziwux.pdf
- https://uploads.strikinglycdn.com/files/3a98aa57-bc6d-4a0e-b919-caa905d75b2f/gilavuge.pdf
- https://uploads.strikinglycdn.com/files/dabd2a8b-5a2f-447f-9a3a-bb7c83f116ac/84946285610.pdf
- https://uploads.strikinglycdn.com/files/58b4636d-ccc1-4906-9660-2a5d9c181b9f/gunarupokulimenagakoluk.pdf
- https://cdn.shopify.com/s/files/1/0486/1512/9256/files/rich_dads_guide_to_investing.pdf
- https://cdn.shopify.com/s/files/1/0488/0557/6869/files/47885638666.pdf
- https://cdn.shopify.com/s/files/1/0434/4319/1969/files/13664139517.pdf
- https://cdn.shopify.com/s/files/1/0432/0329/7438/files/50049642723.pdf
- https://uploads.strikinglycdn.com/files/9f96894f-954c-4066-a2be-384e84ce5c4f/54419698545.pdf
- https://uploads.strikinglycdn.com/files/d2a7a933-4955-4619-be89-180a8e509ab4/rovojilovugurixamowaw.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report