SUSPICIOUS — spyro_attack_of_the_rhynocs.pdf
SUSPICIOUS — spyro_attack_of_the_rhynocs.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b5b4089328613194b5047bd45a1233de2244b9ac7fae3cc3cf00cd02cfd6684c - SHA-1:
e780c2057cd6a622415349de7afd4dd888e68947 - MD5:
c00493afb013d0fcbf2b249b749c054c - ssdeep:
768:RgGzpDne5pevfjPQM/Wy631nOgTwLy0NHjAUL8gfAg4ZYF/cucZz:iGFze5kq7wLztvfT0YVcucZz - TLSH:
T108339EF354D7DD8CBA87AB13E9BB2525508AD38C7226D760448C772C80BCABD7E50960 - Submitted as: spyro_attack_of_the_rhynocs.pdf
- File type: pdf · Size: 51116 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/4dfe5197-6491-4d96-807d-c42d95c00ee0/52203673975.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=spyro%253A+attack+of+the+rhynocs, https://uploads.strikinglycdn.com/files/4dfe5197-6491-4d96-807d-c42d95c00ee0/52203673975.pdf, https://uploads.strikinglycdn.com/files/271a7241-5283-4319-92a5-664f90ebbf33/lotusutuke.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=spyro%253A+attack+of+the+rhynocs
- https://uploads.strikinglycdn.com/files/4dfe5197-6491-4d96-807d-c42d95c00ee0/52203673975.pdf
- https://uploads.strikinglycdn.com/files/271a7241-5283-4319-92a5-664f90ebbf33/lotusutuke.pdf
- https://uploads.strikinglycdn.com/files/d5dfcac4-e8de-4fa9-9a8d-d986192ea383/ribonuvodizuxegupe.pdf
- https://uploads.strikinglycdn.com/files/edbd808f-287e-4cc2-8fc5-78d61c1e3e29/16837703789.pdf
- https://cdn-cms.f-static.net/uploads/4366987/normal_5f87ba9c60f33.pdf
- https://cdn-cms.f-static.net/uploads/4366350/normal_5f8773638eeb3.pdf
- https://cdn-cms.f-static.net/uploads/4370076/normal_5f88472a1a6eb.pdf
- https://cdn-cms.f-static.net/uploads/4367300/normal_5f8ab64a4c19a.pdf
- https://cdn-cms.f-static.net/uploads/4379603/normal_5f8aaef5700bd.pdf
- https://cdn-cms.f-static.net/uploads/4369302/normal_5f8875ed20285.pdf
- https://rewemekekebaz.weebly.com/uploads/1/3/1/4/131406535/2efecb114f5e5.pdf
- https://funiwulew.weebly.com/uploads/1/3/2/8/132814073/4995102.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/5058540.pdf
- https://uploads.strikinglycdn.com/files/15cdae42-a610-41e3-bc9f-a63c6b2c7ebf/wofekupopinowufu.pdf
- https://uploads.strikinglycdn.com/files/16add8b6-299c-47df-96fc-5e39986a091e/94466277383.pdf
- https://uploads.strikinglycdn.com/files/d47fc8c8-5097-479f-8a76-a8cd59c23612/lowegujuribigoje.pdf
- https://uploads.strikinglycdn.com/files/c44c0a92-b72b-44fa-ac89-b10ba3d33894/kunogenanugotikikej.pdf
- https://uploads.strikinglycdn.com/files/226173a9-f243-49c3-80cf-6d7a4ec0b4ab/fujosajal.pdf
- https://uploads.strikinglycdn.com/files/e26a990a-19d4-453c-9a26-496709f03135/tarofinaveparav.pdf
- https://uploads.strikinglycdn.com/files/bbf9b3ba-760d-45b9-9dd6-feef32c2cd44/48364312927.pdf
- https://uploads.strikinglycdn.com/files/41260463-4495-4be3-a9a5-15c64c81b13f/mp3_reed_com.pdf
- https://uploads.strikinglycdn.com/files/599cfb46-2d50-4d0c-8d85-52f6be600960/kiwaxowabizuxapunelo.pdf
- https://uploads.strikinglycdn.com/files/7e2c03fc-80ac-4fe8-b1d5-7df40ec08360/dexusi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- rewemekekebaz.weebly.com
- funiwulew.weebly.com
- fijojonibiw.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report