SUSPICIOUS — rurigam.pdf
SUSPICIOUS — rurigam.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
86788fb5214100b124b196c58d8b73fc8a07df5d56bb8072829bac5eb885a581 - SHA-1:
00068990f691801c3ad3fb51beba9293466bf44e - MD5:
a8a3e8ee9833dccaf27b411622882fa0 - ssdeep:
768:rgGzpDZpcfxulDUVlhneSDQW66rHAYCV0NBE1C30ebuTaic7y2HiO:UGFdWxuidvCV0uCkebuTdc7HCO - TLSH:
T15C32AFF310A7ED4C79879B136EEA1459949AD78C7132E7609998776CC0783BD3F40A20 - Submitted as: rurigam.pdf
- File type: pdf · Size: 45127 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://files.trustbb.com/uploads/1/3/0/8/130874238/4057371.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=caravan+encyclopedia+of+general+knowledge+pdf, http://kotupo.kleinsentertainment.com/uploads/1/3/2/8/132814930/wofokuxamodirin.pdf, http://files.sharlleteaesthetics.com/uploads/1/3/0/7/130776008/nibipa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=caravan+encyclopedia+of+general+knowledge+pdf
- http://kotupo.kleinsentertainment.com/uploads/1/3/2/8/132814930/wofokuxamodirin.pdf
- http://files.sharlleteaesthetics.com/uploads/1/3/0/7/130776008/nibipa.pdf
- http://losifozik.judithfilcwritingservices.com/uploads/1/3/1/3/131384605/1757210.pdf
- http://natari.titanguitars.com/uploads/1/3/2/8/132814838/nidalobovifebal-jadavako.pdf
- http://files.maghknog.com/uploads/1/3/0/7/130775520/8349013.pdf
- http://files.glennartfarm.com/uploads/1/3/0/7/130776898/bedugija_gajoz.pdf
- http://files.trustbb.com/uploads/1/3/0/8/130874238/4057371.pdf
- http://files.ikaruscoffee.co.nz/uploads/1/3/0/8/130813373/fefukuxisi-rakuwusogosu-jadomotujekezoj-kamovu.pdf
- http://files.10komobile.net/uploads/1/3/0/7/130740073/7310944.pdf
- https://cdn.shopify.com/s/files/1/0484/8985/7174/files/49626935184.pdf
- https://cdn.shopify.com/s/files/1/0486/1303/2101/files/91393675126.pdf
- https://cdn.shopify.com/s/files/1/0467/5734/7491/files/xadab.pdf
- https://uploads.strikinglycdn.com/files/d3e4e726-edc9-4575-9755-10fff42195f7/giberikapidi.pdf
- https://uploads.strikinglycdn.com/files/7eb3b780-c4ad-4c70-a9df-e7343a196bd8/84630462616.pdf
- https://uploads.strikinglycdn.com/files/36534270-3ee9-4fb7-867c-47d063857fdb/42980300630.pdf
- https://uploads.strikinglycdn.com/files/579ccad7-97be-4853-801b-b0f0e5f5a9b9/fofakejibaw.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- kotupo.kleinsentertainment.com
- files.sharlleteaesthetics.com
- losifozik.judithfilcwritingservices.com
- natari.titanguitars.com
- files.maghknog.com
- files.glennartfarm.com
- files.trustbb.com
- files.10komobile.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
- files.ikaruscoffee.co.nz
File paths
- m:\jhQ
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report