SUSPICIOUS — nulemuligijog-wofomugudozajut.pdf
SUSPICIOUS — nulemuligijog-wofomugudozajut.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c09f7e25e4bcc23fb3107538077fac7aa2fdb0469e416de8c278d99ba3ba8258 - SHA-1:
c5a442e90ed67ba53883c611d86f94a43b98aa31 - MD5:
de040aed7bc1a4b5fd5e67520b7fb580 - ssdeep:
768:CvgGzpDop/DLm+Lyk9NCfbW5Ub6v472j4wD5LCA09Ti3A8A8wT+lAelZ0KkfPA3l:rGFUpr62j4wFuAae3Av5+R1SA3l - TLSH:
T165328DF7509BEC8C7A869F03AEAA1165118AC7886136D780858C7B6DD1BC77E7F10870 - Submitted as: nulemuligijog-wofomugudozajut.pdf
- File type: pdf · Size: 43429 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/f8766869-133d-4789-b699-5443cbeccf4f/benavupowepixeweb.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=shrek%202%20pc%20game%20full%20version%20free%20do, https://uploads.strikinglycdn.com/files/b6a83fcf-df4c-41d1-a4a6-b69b8bc307dd/vasanujijupagebaxuv.pdf, https://uploads.strikinglycdn.com/files/19385e50-e44e-47f0-bf0f-bb4108a622ee/43359635470.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=shrek%202%20pc%20game%20full%20version%20free%20do
- https://uploads.strikinglycdn.com/files/b6a83fcf-df4c-41d1-a4a6-b69b8bc307dd/vasanujijupagebaxuv.pdf
- https://uploads.strikinglycdn.com/files/19385e50-e44e-47f0-bf0f-bb4108a622ee/43359635470.pdf
- https://uploads.strikinglycdn.com/files/f7893f4a-577b-4691-9ade-f629e2669b7e/lobelewagigelanab.pdf
- https://uploads.strikinglycdn.com/files/f8766869-133d-4789-b699-5443cbeccf4f/benavupowepixeweb.pdf
- https://uploads.strikinglycdn.com/files/76f10d94-0142-4a15-8c36-820c61d47ba1/kajesulevilawojamosene.pdf
- https://site-1042843.mozfiles.com/files/1042843/renault_grand_scenic_2020_owners_manual.pdf
- https://site-1043976.mozfiles.com/files/1043976/logarithm-calculator_worksheet_answer_key.pdf
- https://site-1038583.mozfiles.com/files/1038583/92808083994.pdf
- https://site-1040373.mozfiles.com/files/1040373/gegope.pdf
- https://site-1038511.mozfiles.com/files/1038511/56556427211.pdf
- https://uploads.strikinglycdn.com/files/ee51a06f-1dd8-4612-8f4a-bf29d022ab14/woxafajem.pdf
- https://uploads.strikinglycdn.com/files/38aef3ac-3ddc-4d63-977c-7153d5369dea/51484047604.pdf
- https://uploads.strikinglycdn.com/files/0c8de715-03c5-4b48-b283-131e7594b6de/3634002710.pdf
- https://uploads.strikinglycdn.com/files/b2d6057b-f8f0-41be-978a-845548babc4e/29304920880.pdf
- https://cdn.shopify.com/s/files/1/0438/4574/6838/files/pazoxu.pdf
- https://cdn.shopify.com/s/files/1/0483/4371/1907/files/vimumilawalawetuvedod.pdf
- https://cdn.shopify.com/s/files/1/0486/2613/9294/files/seribu_wajah_ayah.pdf
- https://cdn.shopify.com/s/files/1/0498/0693/4178/files/63175095342.pdf
- https://cdn.shopify.com/s/files/1/0427/8878/2236/files/gattaca_movie_questions_biology.pdf
- https://cdn-cms.f-static.net/uploads/4366956/normal_5f8785d2a3098.pdf
- https://cdn-cms.f-static.net/uploads/4365576/normal_5f88ccec6e1cf.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f875d40d5d7c.pdf
- https://cdn-cms.f-static.net/uploads/4366367/normal_5f8717fd52117.pdf
- https://cdn-cms.f-static.net/uploads/4369317/normal_5f87ebfa43b7b.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1042843.mozfiles.com
- site-1043976.mozfiles.com
- site-1038583.mozfiles.com
- site-1040373.mozfiles.com
- site-1038511.mozfiles.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report