SUSPICIOUS — tiwelaluxon.pdf
SUSPICIOUS — tiwelaluxon.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
87e2a68a3308dcb8724758c522d1f809148b2f76e3b63a9962162d49c0e1a901 - SHA-1:
3ff165884bc2eca0ca351297dd1e39a1fd42c740 - MD5:
dcc4f1377c10b01c01287b59b0c05cb5 - ssdeep:
768:/gGzpD7q7Nn/CZ/giklPKLA8cfGSVvqJecC7SM9t6SIjrBg:IGFHWKgikcLA8cPJqJ/0tFI/Bg - TLSH:
T1C431AEF75457ECCC669AAB03BDE710985145CB483236A76069C877BCC4BC2BCEE10962 - Submitted as: tiwelaluxon.pdf
- File type: pdf · Size: 42900 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/732ab4c7-b0d1-4387-b61f-da149f509daf/zitikuden.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=aluminium+manufacturing+process+pdf, https://uploads.strikinglycdn.com/files/732ab4c7-b0d1-4387-b61f-da149f509daf/zitikuden.pdf, https://uploads.strikinglycdn.com/files/30c8d6b0-b4c9-4bc0-9a07-f53993467eb2/monawaruvowavozimixuve.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=aluminium+manufacturing+process+pdf
- https://uploads.strikinglycdn.com/files/732ab4c7-b0d1-4387-b61f-da149f509daf/zitikuden.pdf
- https://uploads.strikinglycdn.com/files/30c8d6b0-b4c9-4bc0-9a07-f53993467eb2/monawaruvowavozimixuve.pdf
- https://uploads.strikinglycdn.com/files/3c92d53e-4c1a-47c0-be97-dee1495fba10/wefuninuladusodudotuloj.pdf
- https://uploads.strikinglycdn.com/files/29838949-0f20-4895-b583-315fb7546694/97333444964.pdf
- https://cdn.shopify.com/s/files/1/0438/1150/4288/files/yahoo_messenger_apps_free.pdf
- https://cdn.shopify.com/s/files/1/0428/0736/1703/files/badijeta.pdf
- https://cdn.shopify.com/s/files/1/0429/9164/8929/files/humbucker_sized_p90.pdf
- http://files.benjauto.com/uploads/1/3/2/7/132710624/3264554.pdf
- http://files.happy-wife-spirit-life.com/uploads/1/3/0/8/130874676/duvaxemugu_rezuwijazixumo_migiwebila.pdf
- http://files.karenapps.com/uploads/1/3/0/7/130740000/5037454.pdf
- http://files.caiwilliams.com/uploads/1/3/1/6/131606027/dilukixizo-pawako-duviturerelu-robejokor.pdf
- http://files.bigfootyarn.com/uploads/1/3/1/0/131070437/nutuduzabiwak.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- files.benjauto.com
- files.happy-wife-spirit-life.com
- files.karenapps.com
- files.caiwilliams.com
- files.bigfootyarn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report