SUSPICIOUS — luzinajonigiv_namekazegodo_wezidutulemowu_geluxiledow.pdf
SUSPICIOUS — luzinajonigiv_namekazegodo_wezidutulemowu_geluxiledow.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (51/100). 1 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5c97152335e1d592ac631cdf92cd6caec9224d9b3a2d58d433da184bc00fa7a3 - SHA-1:
17bf815d7c8e24362a6d816c471fe20ffa05d76f - MD5:
7af449852b57739e22d0389ac8521175 - ssdeep:
768:NgGzpDKethNsvbnKjpm78JZB8boiQsBJ9D91IeG4gX5fAiO7qTCVRe9:uGFueivP8JZ+8iLv915G4yAXVRe9 - TLSH:
T1B4326CF350E7EE8C7A87EB036EBB259D618AD7482132A7605488672DC4BC67D3F40950 - Submitted as: luzinajonigiv_namekazegodo_wezidutulemowu_geluxiledow.pdf
- File type: pdf · Size: 44802 bytes
- Verdict: suspicious (51/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 51/100 is the fusion of 3 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/e3cc32bb-46e0-4c16-92a1-1572c0b159dc/22533383720.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=electronics%20from%20the%20ground%20up%20pdf%20download, https://uploads.strikinglycdn.com/files/e3cc32bb-46e0-4c16-92a1-1572c0b159dc/22533383720.pdf, https://uploads.strikinglycdn.com/files/b2dd0d1a-d585-4d34-a8c3-d7ad44967dc0/39639078496.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=electronics%20from%20the%20ground%20up%20pdf%20download
- https://uploads.strikinglycdn.com/files/e3cc32bb-46e0-4c16-92a1-1572c0b159dc/22533383720.pdf
- https://uploads.strikinglycdn.com/files/b2dd0d1a-d585-4d34-a8c3-d7ad44967dc0/39639078496.pdf
- https://uploads.strikinglycdn.com/files/908dbbcd-5734-4460-ba92-ff9ff69e541c/xojetabazenovabawarojo.pdf
- https://uploads.strikinglycdn.com/files/f909c70c-14bf-4ac5-aa48-ace177ff02fa/porapezilapiganesutop.pdf
- https://uploads.strikinglycdn.com/files/d3ee266f-9e3e-4311-8d60-d6d5d32ad351/89497560713.pdf
- https://uploads.strikinglycdn.com/files/ddb53a6f-dc66-4bc7-96ab-2812cd14a001/63128869247.pdf
- https://uploads.strikinglycdn.com/files/e036698b-fdde-4c4b-9e17-c67ba2eecb39/92190346340.pdf
- https://jodalutuz.weebly.com/uploads/1/3/4/4/134444421/6714275.pdf
- https://botubadixebom.weebly.com/uploads/1/3/1/4/131407995/b288b48164.pdf
- https://fanavepuru.weebly.com/uploads/1/3/1/8/131871984/gipopodenuvet-viwarizu-xepigegububi.pdf
- https://dubuzosokiboxof.weebly.com/uploads/1/3/1/1/131163723/1c3180a5bee1d84.pdf
- https://sumulejuno.weebly.com/uploads/1/3/4/3/134361372/neledebamep.pdf
- https://kulilopoxi.weebly.com/uploads/1/3/4/3/134375859/vepatumikaremoz-finafamiwawutep-fipejawud-jebake.pdf
- https://sijoxedewi.weebly.com/uploads/1/3/4/3/134346210/xijumiluxemilinad.pdf
- https://dejolezeg.weebly.com/uploads/1/3/2/8/132815968/miwobajiziz_jiwizu_rumuzijotux_xetegowi.pdf
- https://guvapokasek.weebly.com/uploads/1/3/4/4/134437462/f9dd46edfa7.pdf
- https://raxabebawozovi.weebly.com/uploads/1/3/4/3/134311701/nofadexaz-dizopogikib.pdf
- https://uploads.strikinglycdn.com/files/4be880f0-c8c6-4a3a-8c16-ce4d66316dae/49505269630.pdf
- https://uploads.strikinglycdn.com/files/d7997b79-003d-4331-8c52-ddbfcb29d37f/dufufovarasedivemamijox.pdf
- https://cdn.shopify.com/s/files/1/0266/8675/0913/files/wikigusefipotupamenidik.pdf
- https://cdn.shopify.com/s/files/1/0437/9371/1265/files/refactoring_ui_book.pdf
- https://cdn.shopify.com/s/files/1/0501/0613/8787/files/92809000385.pdf
- https://cdn.shopify.com/s/files/1/0484/8975/8875/files/magizorigef.pdf
- https://cdn.shopify.com/s/files/1/0434/1540/4695/files/xizewabolamuzipezanotif.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- jodalutuz.weebly.com
- botubadixebom.weebly.com
- fanavepuru.weebly.com
- dubuzosokiboxof.weebly.com
- sumulejuno.weebly.com
- kulilopoxi.weebly.com
- sijoxedewi.weebly.com
- dejolezeg.weebly.com
- guvapokasek.weebly.com
- raxabebawozovi.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report