SUSPICIOUS — vuvosudojufilonoz.pdf
SUSPICIOUS — vuvosudojufilonoz.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6d2923b76115cd0f0d97da1ba7868f815240e75ef41d7576a5c0f60b00901df9 - SHA-1:
92b351f966f37debd8f203cc5dca367e7eb886d9 - MD5:
4b6f44c95d76da7bfbe4bf61bffc8689 - ssdeep:
768:8gGzpDneI+0iwtrGENufKxijcGCJcwVH23/1Eytd2PufTtr1Yi:ZGFbeyiaCFKXGuvVH0douRr1Yi - TLSH:
T1C7318DF340B7ED8C7AC6AB53AEB61459648D838C2232D76044D8777DC5BC6BD6E00921 - Submitted as: vuvosudojufilonoz.pdf
- File type: pdf · Size: 39715 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/2ac8f5b1-2873-402d-ac00-58fcaa6adabc/40019674551.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=electricity+and+magnetism+pdf+for+bsc, https://uploads.strikinglycdn.com/files/2ac8f5b1-2873-402d-ac00-58fcaa6adabc/40019674551.pdf, https://uploads.strikinglycdn.com/files/0a8c070a-1b4a-4ccb-807f-7b56fa28d195/peradexikon.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=electricity+and+magnetism+pdf+for+bsc
- https://uploads.strikinglycdn.com/files/2ac8f5b1-2873-402d-ac00-58fcaa6adabc/40019674551.pdf
- https://uploads.strikinglycdn.com/files/0a8c070a-1b4a-4ccb-807f-7b56fa28d195/peradexikon.pdf
- https://uploads.strikinglycdn.com/files/d3f5828a-3cbb-4810-820c-457e6041f1f8/71096686253.pdf
- https://uploads.strikinglycdn.com/files/176116f0-27ce-4f08-a6c3-7f2ba2903e55/luxurovud.pdf
- https://uploads.strikinglycdn.com/files/79aead5c-2c63-4c9e-a80c-e550c271fc08/30480602950.pdf
- https://uploads.strikinglycdn.com/files/c947b0d4-5e03-4551-b0f0-40207da1945d/81695975551.pdf
- https://uploads.strikinglycdn.com/files/c3e3a3af-04a4-4156-b37d-7003e094d11b/38159025956.pdf
- https://uploads.strikinglycdn.com/files/b61e6605-7f4a-4280-9705-99bce8c57347/54993915454.pdf
- https://uploads.strikinglycdn.com/files/83a0c963-b4c7-4e55-8110-20a9263e4c20/nikuliwazeka.pdf
- https://site-1042448.mozfiles.com/files/1042448/51163604089.pdf
- https://site-1036907.mozfiles.com/files/1036907/jejusadomuxisetibasilav.pdf
- https://site-1038967.mozfiles.com/files/1038967/49099207614.pdf
- https://site-1040132.mozfiles.com/files/1040132/kaxabonuboraguvizarezowoz.pdf
- https://uploads.strikinglycdn.com/files/9aa89c90-e4d8-4ec9-ae64-4c36cc068d96/dosumadejaxos.pdf
- https://uploads.strikinglycdn.com/files/d1024cd6-6451-4bfe-8fdd-bd53f88db0f8/97704385477.pdf
- https://uploads.strikinglycdn.com/files/57ade072-61ed-46a1-ba9c-eded6635c5eb/tagegeboxomavinitana.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1042448.mozfiles.com
- site-1036907.mozfiles.com
- site-1038967.mozfiles.com
- site-1040132.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report