SUSPICIOUS — rejowedigojibafupa.pdf
SUSPICIOUS — rejowedigojibafupa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c1576e605831985f7d4a9be7fb3341ebb153a7a60c61803a40bcc84aee1c7b9b - SHA-1:
5b473349ed105c7774ec03ce70db8fc8cca777ac - MD5:
91a3ea51d2fc37d11321a7c06ad3483f - ssdeep:
768:WgGzpDWpWmGj/vIDrkIjVl1Hw+FlQ5g6PFe1ERASEcr56N:DGFipY/pIjz9oMmrEcr56N - TLSH:
T18632AEF340A3DD4C7A86AB579DEA149DA14AD38C213697A049CD376CC1BC3AD2F10E91 - Submitted as: rejowedigojibafupa.pdf
- File type: pdf · Size: 45974 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/690a4609-1fc6-4024-b1d6-9754638b593e/gonid.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=failure+of+nerve, https://uploads.strikinglycdn.com/files/a6c32894-bd9b-4e71-806c-b2722ebdb41d/67827118448.pdf, https://uploads.strikinglycdn.com/files/e41cc8f0-b08c-4697-8cd5-f7e49d973cfb/1705336923.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=failure+of+nerve
- https://uploads.strikinglycdn.com/files/a6c32894-bd9b-4e71-806c-b2722ebdb41d/67827118448.pdf
- https://uploads.strikinglycdn.com/files/e41cc8f0-b08c-4697-8cd5-f7e49d973cfb/1705336923.pdf
- https://uploads.strikinglycdn.com/files/b2d411cc-58ab-44de-9b0e-7dd199defec9/vejemozagaluzesutiveki.pdf
- https://uploads.strikinglycdn.com/files/917f0256-dd9f-44ec-8b68-9e7077772051/metalazokigazadulo.pdf
- https://uploads.strikinglycdn.com/files/15594e95-8d4f-4f47-a0dc-0d266ec9bbcf/88169823462.pdf
- https://uploads.strikinglycdn.com/files/ce5dadb2-d6d8-453d-8fe9-b187894161dd/72381945710.pdf
- https://uploads.strikinglycdn.com/files/690a4609-1fc6-4024-b1d6-9754638b593e/gonid.pdf
- https://uploads.strikinglycdn.com/files/d204f69a-0b6d-42de-8697-84c48ab98aaf/xegigaganiwulinuxizozegoz.pdf
- https://uploads.strikinglycdn.com/files/a1b20c57-6bef-4f73-9348-4e4f7954f910/83901283554.pdf
- https://site-1042205.mozfiles.com/files/1042205/22353423114.pdf
- https://site-1039290.mozfiles.com/files/1039290/69781055004.pdf
- https://site-1037094.mozfiles.com/files/1037094/34865482223.pdf
- http://files.mrtmath.org/uploads/1/3/1/4/131406082/fopisa.pdf
- http://files.wizardsfastpitch.net/uploads/1/3/0/9/130969364/gotuburimiv.pdf
- http://vubexukiv.teach-me-today.com/uploads/1/3/1/4/131406710/gavebotiwugilijemub.pdf
- http://files.lucymortonmusic.com/uploads/1/3/1/4/131453016/09817954082.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1042205.mozfiles.com
- site-1039290.mozfiles.com
- site-1037094.mozfiles.com
- files.mrtmath.org
- files.wizardsfastpitch.net
- vubexukiv.teach-me-today.com
- files.lucymortonmusic.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report