SUSPICIOUS — taxajijot.pdf
SUSPICIOUS — taxajijot.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (66/100). 2 of 50 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
74420d9194ebfc5d068d9fe0ca3738f8f77ab80b8f41d35e3ba2c6e33629c896 - SHA-1:
dfcb83c82d56dc9e7f0b7ef28d770208f257cca3 - MD5:
70deda26cc0aa18c67070be53cd343a6 - ssdeep:
768:4gGzpDNeNAprglGzShpg3LXBnzi+JWYXYcXiS4rZrNktw9M2zZFrfuMyFF6geOLq:VGFBeHhALRnz/JWvcya2rfVOLgpFnmE - TLSH:
T11334AEF36097ED8D7A4F9B43ADA710A9604AD78C61328B5054CC6A2CC4BCABD7F10B15 - Submitted as: taxajijot.pdf
- File type: pdf · Size: 56097 bytes
- Verdict: suspicious (66/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 66/100 is the fusion of 7 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/ac6d3bf6-a69c-419b-8a70-2229f498cf4c/6847688157.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=jab%20comix%20siterip, https://cdn-cms.f-static.net/uploads/4368971/normal_5f8b9ccf5924d.pdf, https://cdn-cms.f-static.net/uploads/4366389/normal_5f8735af9eee3.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 13 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=jab%20comix%20siterip
- https://cdn-cms.f-static.net/uploads/4368971/normal_5f8b9ccf5924d.pdf
- https://cdn-cms.f-static.net/uploads/4366389/normal_5f8735af9eee3.pdf
- https://cdn-cms.f-static.net/uploads/4366364/normal_5f870fbad8f3d.pdf
- https://cdn-cms.f-static.net/uploads/4368469/normal_5f8b5b8c7dc13.pdf
- https://cdn-cms.f-static.net/uploads/4367927/normal_5f89f89283e16.pdf
- https://cdn-cms.f-static.net/uploads/4367903/normal_5f875859b2c22.pdf
- https://cdn-cms.f-static.net/uploads/4365598/normal_5f8b80b58be26.pdf
- https://uploads.strikinglycdn.com/files/ac6d3bf6-a69c-419b-8a70-2229f498cf4c/6847688157.pdf
- https://uploads.strikinglycdn.com/files/38150127-2e30-450d-8ccc-436a9018b63d/rurebanidofi.pdf
- https://uploads.strikinglycdn.com/files/e8eb9e82-ce84-4cf5-8d10-d99510a6dea3/51037162785.pdf
- https://uploads.strikinglycdn.com/files/312830b0-1249-4102-8293-6d5f0afb0fd1/soxupawam.pdf
- https://uploads.strikinglycdn.com/files/0eab152c-ccca-41b6-96b8-39f1ebb7670f/14143276672.pdf
- https://cdn.shopify.com/s/files/1/0437/6035/3429/files/comprehension_worksheet_ks2.pdf
- https://cdn.shopify.com/s/files/1/0440/8895/0949/files/pitagog.pdf
- https://cdn.shopify.com/s/files/1/0484/9100/4059/files/26917860738.pdf
- https://cdn.shopify.com/s/files/1/0486/0274/2952/files/time_saving_standards_architecture.pdf
- https://cdn.shopify.com/s/files/1/0481/6093/1991/files/fupewepep.pdf
- https://uploads.strikinglycdn.com/files/57042019-0cb3-4189-bb1f-5e78b1348551/nadonomemulizub.pdf
- https://uploads.strikinglycdn.com/files/47401995-6ad7-41fd-97c8-fb7e4af75e5c/25824836927.pdf
- https://cdn.shopify.com/s/files/1/0440/7777/7061/files/97110684721.pdf
- https://cdn.shopify.com/s/files/1/0482/7073/7563/files/dengeki_bunko_crossing_void_android_download.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report