SUSPICIOUS — xukesinejavetagaji.pdf
SUSPICIOUS — xukesinejavetagaji.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
70dd0428c19cacc75bd79f5266a846a529621823d9ffcda5c876d880457a8f26 - SHA-1:
33963c9896628487a5fb2ad13727ce971d2394eb - MD5:
666b2b972aea4d72ee1eb5de38b71298 - ssdeep:
768:ugGzpDuYmivpg+kvoq71MCS0FvNhKacKTALVtRC0ghfFVh1jFX:LGF6z1FS0Fv3KacKIgNjFX - TLSH:
T1B3327CF75097ED8C7B8AAB8369B7116D504ED38C2132DAA0058C7A2DC43C6BE7E10E51 - Submitted as: xukesinejavetagaji.pdf
- File type: pdf · Size: 46963 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/9316a0f8-afcf-4fe3-83ea-cbf1e82cc520/65192654680.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=save%20as%20pdf%20shortcut%20excel%202016, https://uploads.strikinglycdn.com/files/ddea8fef-c7b6-46b4-8807-ff76c205797e/vaziredozosuwudimud.pdf, https://uploads.strikinglycdn.com/files/3e39eb9a-77d4-4aff-8411-d650ab311a0f/dilakotepuvumagirelaja.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=save%20as%20pdf%20shortcut%20excel%202016
- https://uploads.strikinglycdn.com/files/ddea8fef-c7b6-46b4-8807-ff76c205797e/vaziredozosuwudimud.pdf
- https://uploads.strikinglycdn.com/files/3e39eb9a-77d4-4aff-8411-d650ab311a0f/dilakotepuvumagirelaja.pdf
- https://uploads.strikinglycdn.com/files/81000c57-9911-4192-a707-2ccdd897a444/78729631905.pdf
- https://uploads.strikinglycdn.com/files/af51e7e2-05a9-4b5d-be97-af5213a810c5/ralamurigarazegana.pdf
- https://uploads.strikinglycdn.com/files/56ce2a7d-1517-4dac-adcc-da6789794d52/felony_vs_misdemeanor_worksheet.pdf
- https://uploads.strikinglycdn.com/files/21467183-3142-41b9-94e8-54e9d0aa6105/97992737668.pdf
- https://uploads.strikinglycdn.com/files/d6638f77-fabe-48be-bb75-cfc33454ce53/vorabepisowozupapep.pdf
- https://cdn.shopify.com/s/files/1/0496/9332/7517/files/28353133565.pdf
- https://uploads.strikinglycdn.com/files/9316a0f8-afcf-4fe3-83ea-cbf1e82cc520/65192654680.pdf
- https://uploads.strikinglycdn.com/files/3f845175-b1ce-4b67-ae0c-e45820675e31/cheetah_slide_rite_bags.pdf
- https://uploads.strikinglycdn.com/files/1a7fb89d-61b0-4a61-a408-4e35f776b0be/synchronous_and_asynchronous_counters_in_digital_electronics.pdf
- https://cdn-cms.f-static.net/uploads/4369190/normal_5f996bddcbd70.pdf
- https://cdn-cms.f-static.net/uploads/4410431/normal_5f982e18e8bca.pdf
- https://cdn.shopify.com/s/files/1/0497/9461/3410/files/81206648399.pdf
- https://uploads.strikinglycdn.com/files/d23ad1d4-51e8-46a7-ba1c-821183af9043/que_son_los_helechos_resumen.pdf
- https://uploads.strikinglycdn.com/files/8660df2d-ebb6-4bf2-bd59-925752087d4a/sideways_stories_from_wayside_school_reading_level.pdf
- https://cdn.shopify.com/s/files/1/0492/7527/3372/files/datil_pepper_plants_for_sale_st_augustine.pdf
- https://cdn-cms.f-static.net/uploads/4369328/normal_5f8fe5e291ddc.pdf
- https://uploads.strikinglycdn.com/files/90671db9-f444-4b3e-97e2-7caf2959c51c/filinuwatefejitufalak.pdf
- https://cdn.shopify.com/s/files/1/0437/1909/8523/files/76946819451.pdf
- https://uploads.strikinglycdn.com/files/f3925b41-09c2-49ac-9608-8b2084f2c6bb/lazajefonifobowiz.pdf
- https://uploads.strikinglycdn.com/files/3f4c7a56-956f-402d-91ed-0f302f131c8f/10907127145.pdf
- https://uploads.strikinglycdn.com/files/4c2329e5-8f2e-4dc9-8ef8-d0713366d6d3/15757994314.pdf
- https://uploads.strikinglycdn.com/files/9c87cb44-0488-4705-af0e-6e49f231bebb/77810835612.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report