SUSPICIOUS — pudejusededojabesase.pdf
SUSPICIOUS — pudejusededojabesase.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7d5985027e75fa3dbccba1a0ea36560f13da031fa9cfc800da6645a7ea3464c2 - SHA-1:
424362371032fb6691265ae4c305b1a5c4b5937c - MD5:
07936e5460f94726e57a2f6cf4cf83ec - ssdeep:
768:mgGzpDDpxukrYyO+EgDGgcOBenj/qGXALVuSBtDY/cxzv8Y:zGFPpxVGXOBKj/qOAPbJxzv8Y - TLSH:
T181309EF351ABDC887A87DB438DA610456285D7493032D76499CCBBBDC8BC2BC7E51860 - Submitted as: pudejusededojabesase.pdf
- File type: pdf · Size: 37813 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/88396192-ca14-4dc2-8615-33ba55647695/86844659571.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=portfolio+outdoor+lighting+300w+transformer+manual, http://files.communitysystemsfoundation.org/uploads/1/3/1/3/131397950/mifonik_kilugelowag.pdf, http://pololitax.wmcfp.com/uploads/1/3/0/9/130969060/4340d77884.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=portfolio+outdoor+lighting+300w+transformer+manual
- http://files.communitysystemsfoundation.org/uploads/1/3/1/3/131397950/mifonik_kilugelowag.pdf
- http://pololitax.wmcfp.com/uploads/1/3/0/9/130969060/4340d77884.pdf
- http://faxir.essexcountylc.org/uploads/1/3/0/8/130814030/rubiban-xunupasaxe-peximaveveki-wanez.pdf
- https://uploads.strikinglycdn.com/files/88396192-ca14-4dc2-8615-33ba55647695/86844659571.pdf
- https://uploads.strikinglycdn.com/files/b6b52538-2c27-443d-9dac-6ac33482287e/81894059548.pdf
- http://files.chichestertherapy.com/uploads/1/3/1/6/131606262/7429939.pdf
- http://files.monkeysbnb.com/uploads/1/3/0/7/130739740/wofuwumofomopo.pdf
- http://files.r3dband.com/uploads/1/3/2/8/132814241/7583084.pdf
- http://files.bassittdesigns.com/uploads/1/3/1/3/131378993/lekubuxidupa.pdf
- http://files.davidprossow.com/uploads/1/3/0/9/130969604/ramobimevafelo-jipom.pdf
- http://kijopobo.kellymichellebaker.com/uploads/1/3/0/8/130874679/5673650.pdf
- http://files.whatshouldmykidsread.com/uploads/1/3/0/7/130776449/6682677.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- files.communitysystemsfoundation.org
- pololitax.wmcfp.com
- faxir.essexcountylc.org
- uploads.strikinglycdn.com
- files.chichestertherapy.com
- files.monkeysbnb.com
- files.r3dband.com
- files.bassittdesigns.com
- files.davidprossow.com
- kijopobo.kellymichellebaker.com
- files.whatshouldmykidsread.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report