SUSPICIOUS — gagatobosisivexawolo.pdf
SUSPICIOUS — gagatobosisivexawolo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
74e2083bfcec9dc7d031bca59679c2c985597e89647a0d50c77b1fa8a3cb4d97 - SHA-1:
58b026a6ea95974870ddab6ae4b5c0e38a87e56a - MD5:
31d91aa3183a8e6062470520c407dcf7 - ssdeep:
768:jgGzpDGsb7Ph2jfzRZF7x2/Bak95ZKeXrw/6YNC3lL2L4geklDhA:cGFisBBXZzC6YcVL8tDlDhA - TLSH:
T19632ADF31567ED4E39C7A783ADA706496089C6883177A760049C3B2CD1B84FDBF129A0 - Submitted as: gagatobosisivexawolo.pdf
- File type: pdf · Size: 44723 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/6b720b80-6af7-4e94-8ed9-d2d5a1bede99/85642963128.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=bronchiolite+virale+chez+nourrisson+pdf, https://cdn.shopify.com/s/files/1/0438/0586/8193/files/wall_street_jumping_out_windows.pdf, https://cdn.shopify.com/s/files/1/0429/8866/7034/files/most_cuda_cores.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=bronchiolite+virale+chez+nourrisson+pdf
- https://cdn.shopify.com/s/files/1/0438/0586/8193/files/wall_street_jumping_out_windows.pdf
- https://cdn.shopify.com/s/files/1/0429/8866/7034/files/most_cuda_cores.pdf
- https://cdn.shopify.com/s/files/1/0434/7448/5400/files/79239559170.pdf
- https://cdn.shopify.com/s/files/1/0434/6016/5797/files/biopsychology_10th_edition_john_pinel_steven_barnes.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/97242885008.pdf
- https://cdn.shopify.com/s/files/1/0433/6271/3754/files/45990749201.pdf
- https://cdn.shopify.com/s/files/1/0429/5789/7882/files/direct_joint_and_inverse_variation_worksheet.pdf
- https://uploads.strikinglycdn.com/files/6b720b80-6af7-4e94-8ed9-d2d5a1bede99/85642963128.pdf
- https://uploads.strikinglycdn.com/files/6c62251a-b061-43f6-bcb3-6d8f7bde3b60/50932862451.pdf
- https://uploads.strikinglycdn.com/files/dc336f04-d6c4-4cbb-b7ee-6d3ac682b8fb/89802269303.pdf
- https://uploads.strikinglycdn.com/files/18e25a20-1474-4593-b0cd-648d26dd8afe/30539129494.pdf
- https://uploads.strikinglycdn.com/files/c8461d8c-10bc-443b-8df8-8fd0edc3d5fa/61695368447.pdf
- https://cdn.shopify.com/s/files/1/0480/8124/0228/files/puzibewag.pdf
- https://cdn.shopify.com/s/files/1/0430/6563/9069/files/42959618522.pdf
- https://cdn.shopify.com/s/files/1/0432/7263/4533/files/69535193296.pdf
- https://cdn.shopify.com/s/files/1/0433/9954/4984/files/zuzusomazane.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report