SUSPICIOUS — kinijokubusorikedigam.pdf
SUSPICIOUS — kinijokubusorikedigam.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
77a6fa558aeebd853bf4650c495f7cbd09d10c332cd4660484cd5d499de2d00e - SHA-1:
28faa161416cf5b291d5082afa1ee626b6e69378 - MD5:
82edae6cdb787641b314eae1bb186d2a - ssdeep:
768:xgGzpDnJN19clPexWsC81D8RjfWWICpfwDjVej8ncFl+Q5g:CGFF4iWs114RjlTfwDQVFll5g - TLSH:
T1E9319DF3619BEC887AC6AB477DAA0054504AC789323297B409CC776CD4B85FDBE119B0 - Submitted as: kinijokubusorikedigam.pdf
- File type: pdf · Size: 42787 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/73f1fd88-da69-4709-a896-576d1c1ef6b4/86399712616.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=b.+ed+online+form+in+jharkhand, https://uploads.strikinglycdn.com/files/73f1fd88-da69-4709-a896-576d1c1ef6b4/86399712616.pdf, https://uploads.strikinglycdn.com/files/b3166365-a001-4f8a-a617-71670e08597a/46355324060.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=b.+ed+online+form+in+jharkhand
- https://uploads.strikinglycdn.com/files/73f1fd88-da69-4709-a896-576d1c1ef6b4/86399712616.pdf
- https://uploads.strikinglycdn.com/files/b3166365-a001-4f8a-a617-71670e08597a/46355324060.pdf
- https://uploads.strikinglycdn.com/files/623663e0-af7c-41f7-874e-010085679b65/givikuku.pdf
- http://files.caretwentyfour.net/uploads/1/3/2/7/132740978/2f86362.pdf
- http://files.jongunnfitness.com/uploads/1/3/1/6/131607208/e9491bae.pdf
- http://zesud.placesbeyondwords.com/uploads/1/3/1/6/131637814/rimixikireko_zidekuwutobofo_zilofidisanof_jupatutubijufok.pdf
- http://begufizu.mrshandyman.net/uploads/1/3/0/9/130969352/e9aa9fc71c.pdf
- https://cdn.shopify.com/s/files/1/0480/6485/6228/files/52170919971.pdf
- https://cdn.shopify.com/s/files/1/0432/2240/1192/files/resurreccion_de_jesus_dibujo.pdf
- https://cdn.shopify.com/s/files/1/0485/9291/2549/files/download_market_helper_apk_versi_terbaru.pdf
- https://cdn.shopify.com/s/files/1/0500/4155/3046/files/identify_parts_of_a_circle_worksheet.pdf
- https://uploads.strikinglycdn.com/files/dfe9b181-e5f5-4426-a7f2-e0d7195af5a8/65528305772.pdf
- https://uploads.strikinglycdn.com/files/5839a875-73bb-4b9f-8126-6d36b786227b/54796295732.pdf
- https://uploads.strikinglycdn.com/files/d9004748-5fbb-4dc9-bc7d-7fee5536cfc4/12635776034.pdf
- https://uploads.strikinglycdn.com/files/ecb22940-bab8-446b-a171-e06b461bccad/6877390532.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- files.caretwentyfour.net
- files.jongunnfitness.com
- zesud.placesbeyondwords.com
- begufizu.mrshandyman.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report