SUSPICIOUS — totaruwatonepo.pdf
SUSPICIOUS — totaruwatonepo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ba38f1ed490debb7d7bd0b2eee0422257730063c91f406146e872efe1674b53c - SHA-1:
bd1c206b21b501106ba7fa7741317cc0160421f9 - MD5:
18e53a8b0a58b6310d9a6481b08db38c - ssdeep:
768:xgGzpDWUAJayLhj7bKKRd1oMF0bQCfZemr6gI:CGFyUAn9vbDRd9Zpmr6gI - TLSH:
T16B2F7CF39097DD8C7ECBAB03AAA60565614AD38C312792A005C8773DD0BC5FE3E10A61 - Submitted as: totaruwatonepo.pdf
- File type: pdf · Size: 34991 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/790292a4-e6f2-4b6f-87d8-112541159084/pajofizezifaxo.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=the+count+of+monte+cristo+oxford+dominoes+three+pdf, https://uploads.strikinglycdn.com/files/790292a4-e6f2-4b6f-87d8-112541159084/pajofizezifaxo.pdf, https://uploads.strikinglycdn.com/files/975a14c0-9834-41ca-8d8a-724a5a48d909/tuwiwiwovabazizigidufuman.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=the+count+of+monte+cristo+oxford+dominoes+three+pdf
- https://uploads.strikinglycdn.com/files/790292a4-e6f2-4b6f-87d8-112541159084/pajofizezifaxo.pdf
- https://uploads.strikinglycdn.com/files/975a14c0-9834-41ca-8d8a-724a5a48d909/tuwiwiwovabazizigidufuman.pdf
- https://uploads.strikinglycdn.com/files/99b36c24-00b3-4dc4-95af-aa912ce8bc36/6924181113.pdf
- https://uploads.strikinglycdn.com/files/950ba1b2-cdd9-4436-b5e9-76835ecbb59e/33792102549.pdf
- https://uploads.strikinglycdn.com/files/9695b448-69d4-4c08-9fdb-ac85dc9c82f0/xuxuzalojakojivupelajewam.pdf
- https://site-1041846.mozfiles.com/files/1041846/33146525023.pdf
- https://site-1038555.mozfiles.com/files/1038555/xebowuwag.pdf
- https://site-1037055.mozfiles.com/files/1037055/venunalejolabof.pdf
- https://uploads.strikinglycdn.com/files/602116b2-ba80-48a9-bf91-e97d69974b3f/jumonunozezigopez.pdf
- https://uploads.strikinglycdn.com/files/bb3ea7b2-b773-4d25-8b28-dc0a0b6abe7e/91860229635.pdf
- https://uploads.strikinglycdn.com/files/fbce2703-a397-41ec-abc0-d0676887b265/kifagosunal.pdf
- https://uploads.strikinglycdn.com/files/1bf463c1-d5dc-4f4f-8084-b9abd98827b4/waniwedukepuperejipedalur.pdf
- https://uploads.strikinglycdn.com/files/c1af0356-67f1-426f-9869-c093d9873e18/batitixironaja.pdf
- https://uploads.strikinglycdn.com/files/1c2a06f7-950c-4c70-9b36-4337eda774f8/zipuzavuvi.pdf
- https://uploads.strikinglycdn.com/files/71b97af7-29d4-4091-a832-bb1edb6e70cc/levejuduwanudovif.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1041846.mozfiles.com
- site-1038555.mozfiles.com
- site-1037055.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report