SUSPICIOUS — nisugavupopojob.pdf
SUSPICIOUS — nisugavupopojob.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7da64b1401a8c0b5ee7b656c839de46a30e87cef532fc30e58da3e80e2703392 - SHA-1:
e9dbbebab56a8bb318013e5cc88296446a849958 - MD5:
fe5d0474e666c23f80453d4b2580685e - ssdeep:
1536:OGF2pByiIZQT+NuZCFV/RLEfZ9MTg3wVS1yWeXzIT1Xa4G:3F2pByfZS+VFV/t4Z9Qg314XzIT1O - TLSH:
T140389DF30497DC9DBADBDF43A9A72425740BC78862238AA4489C7A3CC4BC67D6E10911 - Submitted as: nisugavupopojob.pdf
- File type: pdf · Size: 77480 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/fdd42dda-a2ff-4a33-aae9-db5559c324b2/99242757589.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=tubidy%20klip%20indir, https://uploads.strikinglycdn.com/files/fdd42dda-a2ff-4a33-aae9-db5559c324b2/99242757589.pdf, https://uploads.strikinglycdn.com/files/7cd8898b-d9c2-41bb-a675-22a7db1881ae/79202303715.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=tubidy%20klip%20indir
- https://uploads.strikinglycdn.com/files/fdd42dda-a2ff-4a33-aae9-db5559c324b2/99242757589.pdf
- https://uploads.strikinglycdn.com/files/7cd8898b-d9c2-41bb-a675-22a7db1881ae/79202303715.pdf
- https://uploads.strikinglycdn.com/files/e14299af-991f-4e2c-8d7e-fb23de93ce4e/93255041133.pdf
- https://uploads.strikinglycdn.com/files/4ec461c5-c033-4f29-8a24-d7780fcd236d/viwubokitezajitubujibuv.pdf
- https://uploads.strikinglycdn.com/files/25e94961-d743-41e7-ac2e-dc429628331a/4254967777.pdf
- https://cdn.shopify.com/s/files/1/0499/8332/4320/files/du_battery_server_pro.pdf
- https://cdn.shopify.com/s/files/1/0437/8047/2984/files/darerez.pdf
- https://cdn.shopify.com/s/files/1/0266/9536/8888/files/digezowedudutur.pdf
- https://uploads.strikinglycdn.com/files/16b14542-0d8a-4bbf-9afa-0a911c674930/60266806495.pdf
- https://uploads.strikinglycdn.com/files/b3ae8a6f-7dc6-4ec6-a34d-d4d116aa2aec/18316789409.pdf
- https://uploads.strikinglycdn.com/files/67eed496-b4c8-4bbf-a9e5-0b5113b18843/juxazenedekejovamesilum.pdf
- https://topodomero.weebly.com/uploads/1/3/2/6/132696018/4009d9a1.pdf
- https://rakamukomegu.weebly.com/uploads/1/3/2/6/132681656/joralazokeke.pdf
- https://zuwumepegowivos.weebly.com/uploads/1/3/1/0/131069935/360332.pdf
- https://cdn.shopify.com/s/files/1/0492/3896/6438/files/87369807913.pdf
- https://cdn.shopify.com/s/files/1/0480/0184/3359/files/wurukutis.pdf
- https://cdn.shopify.com/s/files/1/0459/8824/9757/files/xezavexujakufexuxa.pdf
- https://uploads.strikinglycdn.com/files/fd4056dc-bb19-4fe0-a5fc-f9179c08935f/54204065506.pdf
- https://uploads.strikinglycdn.com/files/a1f8ef6d-44f0-499f-9305-55945c33407c/26433760042.pdf
- https://uploads.strikinglycdn.com/files/a5fc5977-b825-4a9b-8d52-07dddf7adaba/balavanuxasujimixonalezos.pdf
- https://uploads.strikinglycdn.com/files/26dcef9d-d4a8-4d34-9087-c52bcd387182/95775569921.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- topodomero.weebly.com
- rakamukomegu.weebly.com
- zuwumepegowivos.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report