SUSPICIOUS — vurelif.pdf
SUSPICIOUS — vurelif.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bd7032e3c9f20ef13198ebcf9fd2b491abbdacdbe27d39a6b88350883833db82 - SHA-1:
5e09b8ad6f69f4ee2945cff3a80af3400c73a9e6 - MD5:
19b25cc24d250392a54c78913eac2066 - ssdeep:
1536:aGFeJ8M2HWBkFvAmTIS6j8DjgOwK9LyXqU:DFeyMeNNTQMLwK9LpU - TLSH:
T19C33BFF78097DDCC6BCA7B176AE60469608AD74915739BA0A4C43B6CC4BC6BC3E10A50 - Submitted as: vurelif.pdf
- File type: pdf · Size: 50515 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/b3f35843-a326-48d0-87bd-ae8dbf58023e/12537725818.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=celi+3+test+pdf, https://uploads.strikinglycdn.com/files/b3f35843-a326-48d0-87bd-ae8dbf58023e/12537725818.pdf, https://uploads.strikinglycdn.com/files/9df6d1c4-9729-4f34-b20f-f96c5ed3241a/64971775007.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=celi+3+test+pdf
- https://uploads.strikinglycdn.com/files/b3f35843-a326-48d0-87bd-ae8dbf58023e/12537725818.pdf
- https://uploads.strikinglycdn.com/files/9df6d1c4-9729-4f34-b20f-f96c5ed3241a/64971775007.pdf
- https://uploads.strikinglycdn.com/files/2dfe6e0c-8660-4a34-8c72-f296ac650379/67807122299.pdf
- https://uploads.strikinglycdn.com/files/ca1a5b6a-25e1-4842-a354-ce6fd48440d7/pudofeliwuduribetotafijox.pdf
- https://site-1037886.mozfiles.com/files/1037886/85160077566.pdf
- https://site-1039633.mozfiles.com/files/1039633/42698910491.pdf
- https://uploads.strikinglycdn.com/files/5ac2e888-525d-45ae-ab1b-be6d41dfdeaa/rerodezovebo.pdf
- https://uploads.strikinglycdn.com/files/ff38e124-6bda-41c7-b999-a2afd64f2b81/57905106126.pdf
- https://uploads.strikinglycdn.com/files/f41485f7-43b7-4a86-8fe8-db90b05962cc/loxewimudakapemati.pdf
- https://uploads.strikinglycdn.com/files/29945f9e-d018-4741-831d-60bd605b0e78/xogumasoxixobatoxenolebos.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1037886.mozfiles.com
- site-1039633.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report