SUSPICIOUS — jotoxapabatadumifukepoban.pdf
SUSPICIOUS — jotoxapabatadumifukepoban.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
65b0cb77c66da8c27c1e5f19119026278e2bebd947abc2183c925b9b3c74e1cd - SHA-1:
2b1fca815bcfbcbbbda18aa386eb1ac2e5ce01ec - MD5:
31ec282c2952388d764927fbba104acc - ssdeep:
768:SgGzpDKXYiPgSjVnI4ACDxzhZ1AbF0kSaNw1nQiVfabg6p3M:PGFuoUVVnIbCDxzhsh0kSaNwJQiVfakZ - TLSH:
T137309EF350A7DD9C3A93AB03AEA605996149C78D3237A77048CC376CC4BC2BD6D21961 - Submitted as: jotoxapabatadumifukepoban.pdf
- File type: pdf · Size: 39290 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/a24efc72-5c6b-4810-aad6-53787db73ef2/gamimiwezixebo.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=general+rules+of+active+and+passive+voice+pdf, https://uploads.strikinglycdn.com/files/a24efc72-5c6b-4810-aad6-53787db73ef2/gamimiwezixebo.pdf, https://uploads.strikinglycdn.com/files/ea316584-de91-4038-8945-d863b245a345/telepe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=general+rules+of+active+and+passive+voice+pdf
- https://uploads.strikinglycdn.com/files/a24efc72-5c6b-4810-aad6-53787db73ef2/gamimiwezixebo.pdf
- https://uploads.strikinglycdn.com/files/ea316584-de91-4038-8945-d863b245a345/telepe.pdf
- https://uploads.strikinglycdn.com/files/cdce1a62-5f79-4336-ac34-76818d95a18f/wavinovumekubawe.pdf
- https://uploads.strikinglycdn.com/files/07c150c8-7f5f-4814-9815-a4eb02fba53a/98846706030.pdf
- https://uploads.strikinglycdn.com/files/bc2e8ebe-0cdb-4687-9e90-deb1476de4fb/kujawejomiwazusunakoni.pdf
- http://files.quintamke.com/uploads/1/3/0/7/130775723/543bcce0831.pdf
- http://files.sinisterkiss.com/uploads/1/3/0/9/130969435/zavafiviredatek.pdf
- http://files.diggingupyourrootsbyashley.com/uploads/1/3/1/3/131380008/vodunuvo.pdf
- http://bamoraj.maconretirementeasy.com/uploads/1/3/0/7/130775958/kerakirejefatu.pdf
- http://files.homescholars.org/uploads/1/3/1/3/131398504/zetuforodowelol-dubugo-nizatotekaj-mojatukilu.pdf
- http://files.annedesantis.com/uploads/1/3/1/4/131407511/60ea72be4f.pdf
- http://files.lifesgeneralist.com/uploads/1/3/1/4/131454207/7891918.pdf
- http://files.triciadeed.com/uploads/1/3/0/7/130739489/243f80d1bb4d94.pdf
- http://files.judy-klass.com/uploads/1/3/0/8/130874058/4a9f6.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- files.quintamke.com
- files.sinisterkiss.com
- files.diggingupyourrootsbyashley.com
- bamoraj.maconretirementeasy.com
- files.homescholars.org
- files.annedesantis.com
- files.lifesgeneralist.com
- files.triciadeed.com
- files.judy-klass.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report