SUSPICIOUS — juvagapejaxemudu.pdf
SUSPICIOUS — juvagapejaxemudu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
86ade652a6f1576f3b8d9dfce8dda665632bf0f534dbc7f6db433adfa752d2fc - SHA-1:
44607914fbe0c851970f8f947b12800a648602e9 - MD5:
2c19215da96bda812cf348afd46d30fa - ssdeep:
768:VgGzpDre4H7rxJkBWDk8tTp0uTIEj0PuJD0s84v3CkXXWisCVW4TxV:GGFve4brxhkWsi0PuJDw+CNisgnTxV - TLSH:
T186339EF34167EC8C768E7B036DEB11A9504AC7897132AB6058DC7B6CC47C6BD6E10A60 - Submitted as: juvagapejaxemudu.pdf
- File type: pdf · Size: 48999 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/c60d66d7-1914-4a2c-813d-e22fad315b73/61164156658.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=divinity+original+sin+2+ryker+house, https://uploads.strikinglycdn.com/files/c60d66d7-1914-4a2c-813d-e22fad315b73/61164156658.pdf, https://uploads.strikinglycdn.com/files/53efe7c5-ee3b-48b2-8a74-915dec77420c/xavalexejizarogajulopereg.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=divinity+original+sin+2+ryker+house
- https://uploads.strikinglycdn.com/files/c60d66d7-1914-4a2c-813d-e22fad315b73/61164156658.pdf
- https://uploads.strikinglycdn.com/files/53efe7c5-ee3b-48b2-8a74-915dec77420c/xavalexejizarogajulopereg.pdf
- https://uploads.strikinglycdn.com/files/a217a4d5-239a-4a3b-aaeb-95f45256ee09/66392831070.pdf
- https://cdn.shopify.com/s/files/1/0458/5658/7929/files/sazinuzefovipot.pdf
- https://cdn.shopify.com/s/files/1/0486/3806/6856/files/64316742707.pdf
- https://cdn.shopify.com/s/files/1/0427/9821/9420/files/the_handmaids_tale_book_online.pdf
- https://cdn.shopify.com/s/files/1/0431/7180/7394/files/73730955907.pdf
- https://site-1041501.mozfiles.com/files/1041501/42593894143.pdf
- https://site-1042551.mozfiles.com/files/1042551/kewepaberim.pdf
- https://site-1040780.mozfiles.com/files/1040780/jidupilewamulufukinowofi.pdf
- https://site-1037207.mozfiles.com/files/1037207/jinibuvuvuxumo.pdf
- https://uploads.strikinglycdn.com/files/e162af3e-90b6-4f69-a87c-cee27aecb5cd/34739435180.pdf
- https://uploads.strikinglycdn.com/files/0dfa7976-62e5-4a2d-8c97-687431176e6d/33790384591.pdf
- https://uploads.strikinglycdn.com/files/f0f1a84d-1d29-4777-aff5-ae64956fdf80/97360839802.pdf
- https://uploads.strikinglycdn.com/files/1ce1c81b-2a0e-4722-b4b8-1e75f6d40063/41785058452.pdf
- https://uploads.strikinglycdn.com/files/35b7686e-e528-4894-94a2-8a98b54e80ab/20341899931.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1041501.mozfiles.com
- site-1042551.mozfiles.com
- site-1040780.mozfiles.com
- site-1037207.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report