SUSPICIOUS — book_of_hours_rilke.pdf
SUSPICIOUS — book_of_hours_rilke.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a1616cba91f3c2c858d452315d673d4d37462bc99f499a3f3a81e224900d5835 - SHA-1:
387ae55b63b57c6a85075f38397e0e81a3d43842 - MD5:
4271b7194b3371bf1518f1b597b98e68 - ssdeep:
768:0gGzpD5poNqItk3fKeNdEUIQKbg0SdaRG+zwunj6m00Cxhds4fsh:BGF9p2t0dEUIJg0jRG+znjp3Kzs4fsh - TLSH:
T1D1327DF750E3EC8C7A8B6F039EBB10A9514EC289613697A0048C735ED47C5EE7E50A61 - Submitted as: book_of_hours_rilke.pdf
- File type: pdf · Size: 45165 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/080690ae-f08b-486d-8bd4-94a3b795ee57/pogefe.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=book+of+hours+rilke+pdf, https://uploads.strikinglycdn.com/files/2aafd3ad-830f-41c7-a211-de19c8e21cc9/50659469725.pdf, https://uploads.strikinglycdn.com/files/080690ae-f08b-486d-8bd4-94a3b795ee57/pogefe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=book+of+hours+rilke+pdf
- https://uploads.strikinglycdn.com/files/2aafd3ad-830f-41c7-a211-de19c8e21cc9/50659469725.pdf
- https://uploads.strikinglycdn.com/files/080690ae-f08b-486d-8bd4-94a3b795ee57/pogefe.pdf
- https://uploads.strikinglycdn.com/files/bef6e843-52fe-4271-9238-aa2a3da85443/dulajasekadi.pdf
- https://uploads.strikinglycdn.com/files/d3ca0f2f-f08b-4b69-b0c0-f1173c6f2ef4/napemez.pdf
- https://uploads.strikinglycdn.com/files/d11d9019-6c2d-45ba-8d1a-13e25e064755/rexivukepebesujewena.pdf
- https://wefamojugibe.weebly.com/uploads/1/3/1/1/131164519/tedawonuf.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/44d87feaf8ee.pdf
- https://uploads.strikinglycdn.com/files/c8461d8c-10bc-443b-8df8-8fd0edc3d5fa/61695368447.pdf
- https://uploads.strikinglycdn.com/files/9ece1553-b7b2-4849-b799-7ab11fd49501/99616290218.pdf
- https://uploads.strikinglycdn.com/files/a7f018a4-43fa-49ec-8c73-36784fb2c9cc/19930296760.pdf
- https://uploads.strikinglycdn.com/files/a6b60004-524f-4ef7-862e-7c2e303749ea/28290576234.pdf
- https://uploads.strikinglycdn.com/files/97a19c1e-56f3-4b41-882c-83e156c58460/ripetipefajuzuwaku.pdf
- https://jawowigo.weebly.com/uploads/1/3/0/7/130774982/lewana_rodefimap.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/199877.pdf
- https://xojisige.weebly.com/uploads/1/3/1/6/131637148/dolunabijosim.pdf
- https://rivisoni.weebly.com/uploads/1/3/0/7/130739016/8438487.pdf
- https://uploads.strikinglycdn.com/files/c3601df2-502f-4238-a1db-ce4807ecab1f/jikowod.pdf
- https://uploads.strikinglycdn.com/files/07d51254-fedc-40b8-9870-54add3ca7917/63872832109.pdf
- https://uploads.strikinglycdn.com/files/3d7cdc87-e6f3-4135-935c-1fc9b21755ae/wibedipiwisefowi.pdf
- https://uploads.strikinglycdn.com/files/486f75c2-36de-404f-b730-001e6f0905ce/janevunofobizavilalutozi.pdf
- https://uploads.strikinglycdn.com/files/e45a2b01-8eec-4226-9669-700b5cc52a3f/46983205272.pdf
- https://cdn.shopify.com/s/files/1/0503/3358/1462/files/pa_inheritance_tax_rev_1500_instructions.pdf
- https://cdn.shopify.com/s/files/1/0503/7024/8902/files/interpersonal_psychotherapy_a_clinicians_guide.pdf
- https://cdn.shopify.com/s/files/1/0497/7888/4759/files/football_game_pes_2020_apk.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- wefamojugibe.weebly.com
- mojivimimujovo.weebly.com
- jawowigo.weebly.com
- mogilifus.weebly.com
- xojisige.weebly.com
- rivisoni.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report