SUSPICIOUS — japelareneka-fepat.pdf
SUSPICIOUS — japelareneka-fepat.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b3196ed856be590323412d051ca236f55725fbc074322b56842a4025bb3b812f - SHA-1:
2681afc79274cadda900a067fb79aeb005142066 - MD5:
a2d5d1de0240765063f67ed90aacde4f - ssdeep:
1536:wGFjpw+Tacxf8KdRhzFcYot7+dccFwrFsWBzHhSXxWfKs5Wd52:9FjpPTacxkKhOY+eTAHhYoKyWO - TLSH:
T15336ADF3509BDD8CBEC7AB03ADBB1565608AC74C6133AA5044987B6DC4BC6BD6F10890 - Submitted as: japelareneka-fepat.pdf
- File type: pdf · Size: 65526 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/dd00b51a-0aa9-4443-a4e8-d150ac9deba3/22880231595.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=sniper%20ghost%20warrior%203%20dlc, https://uploads.strikinglycdn.com/files/6b2dadac-1a9a-486e-9951-0d93a90e3cbb/94115812988.pdf, https://uploads.strikinglycdn.com/files/f9e11f4f-b360-43d5-922d-b59b1e6b63c1/sisotuliro.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=sniper%20ghost%20warrior%203%20dlc
- https://uploads.strikinglycdn.com/files/6b2dadac-1a9a-486e-9951-0d93a90e3cbb/94115812988.pdf
- https://uploads.strikinglycdn.com/files/f9e11f4f-b360-43d5-922d-b59b1e6b63c1/sisotuliro.pdf
- https://uploads.strikinglycdn.com/files/d50b223f-b2ce-4bf5-a581-42419df31d4d/30823595592.pdf
- https://uploads.strikinglycdn.com/files/fb9113a1-43f3-497e-b6d0-690a5b4a901f/sutepatoxarewu.pdf
- https://site-1042875.mozfiles.com/files/1042875/rivetuvulebomivavup.pdf
- https://site-1042880.mozfiles.com/files/1042880/society_bye_laws_2020_in_english.pdf
- https://uploads.strikinglycdn.com/files/542fbf7d-154f-45b2-92f2-54db56d869cd/valofumulefos.pdf
- https://uploads.strikinglycdn.com/files/dd00b51a-0aa9-4443-a4e8-d150ac9deba3/22880231595.pdf
- https://uploads.strikinglycdn.com/files/7f92bfea-7d8a-41d5-8d35-dd563e972037/61967822473.pdf
- https://uploads.strikinglycdn.com/files/01c08eec-6a77-4ff0-a8af-2808a152d6bf/riwexorit.pdf
- https://uploads.strikinglycdn.com/files/779f8c27-4b8c-4e8c-9dcc-194ac6e3e1e2/zinevezuvoxijurowupugaba.pdf
- https://uploads.strikinglycdn.com/files/b35af4c6-12b7-492a-bf23-ce1ab23bf062/53551868863.pdf
- https://uploads.strikinglycdn.com/files/a1bb7490-c7b1-45fc-9b28-7641ee0c283a/bexotupitipakavoxugufal.pdf
- https://uploads.strikinglycdn.com/files/6799bd92-bb3c-49fa-947a-22a92e832e78/80309344304.pdf
- https://uploads.strikinglycdn.com/files/67699101-8865-43aa-9fde-a75f4505c8b9/6133339402.pdf
- https://uploads.strikinglycdn.com/files/e7ad1781-ea76-47d6-9b5c-d15b92f6cd0f/momavojumaruji.pdf
- https://site-1039925.mozfiles.com/files/1039925/40303266158.pdf
- https://site-1037858.mozfiles.com/files/1037858/40081538810.pdf
- https://site-1043647.mozfiles.com/files/1043647/89587366747.pdf
- https://site-1039671.mozfiles.com/files/1039671/25567789689.pdf
- https://site-1037086.mozfiles.com/files/1037086/liviwojogivegoxafimo.pdf
- https://site-1043939.mozfiles.com/files/1043939/17567257712.pdf
- https://site-1037061.mozfiles.com/files/1037061/jinunoruvuvogi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1042875.mozfiles.com
- site-1042880.mozfiles.com
- site-1039925.mozfiles.com
- site-1037858.mozfiles.com
- site-1043647.mozfiles.com
- site-1039671.mozfiles.com
- site-1037086.mozfiles.com
- site-1043939.mozfiles.com
- site-1037061.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report