SUSPICIOUS — zezenokapegilupovunixad.pdf
SUSPICIOUS — zezenokapegilupovunixad.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c7bb1b91aed50e142ea1fa1a730e5b276de3d243a9c76fdec80da59ef88f92fb - SHA-1:
b567590f448734de28dcefb7a5183bd3a2830c96 - MD5:
261e85e2eaedebd9d31ead7d1752e296 - ssdeep:
768:fgGzpDa7WeSmU8J9gloxjFqvlZpxwzv+f3AciJ2PBCwRzT:oGFGSpupF4ZnU+YciJIBCwRzT - TLSH:
T1B932AEF311A7ED8D75879F13ACEA1899518AC388B133976454CDB32CD4BC6ADAF10520 - Submitted as: zezenokapegilupovunixad.pdf
- File type: pdf · Size: 43737 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://files.mrwhitchermath.com/uploads/1/3/1/8/131871433/bea2c283.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=jedi+tunic+pattern, http://files.mrwhitchermath.com/uploads/1/3/1/8/131871433/bea2c283.pdf, http://files.insightsmanila.com/uploads/1/3/1/4/131437139/9853391.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=jedi+tunic+pattern
- http://files.mrwhitchermath.com/uploads/1/3/1/8/131871433/bea2c283.pdf
- http://files.insightsmanila.com/uploads/1/3/1/4/131437139/9853391.pdf
- http://buteta.suzannedemontignycounseling.com/uploads/1/3/2/6/132695615/rebedisuba_moduzokiwafar_pubujinipiguza.pdf
- http://files.claphands.net/uploads/1/3/0/8/130874569/kafuxedefutino.pdf
- https://cdn.shopify.com/s/files/1/0482/2840/1309/files/skam_france_season_3_episode_9.pdf
- https://cdn.shopify.com/s/files/1/0435/6633/4111/files/41362738027.pdf
- https://cdn.shopify.com/s/files/1/0431/3382/9277/files/21586004541.pdf
- https://cdn.shopify.com/s/files/1/0478/3885/5327/files/meg_ryan_height_weight.pdf
- https://cdn.shopify.com/s/files/1/0433/2411/3049/files/wefozatipamajetupe.pdf
- https://site-1039143.mozfiles.com/files/1039143/94296287505.pdf
- https://site-1036742.mozfiles.com/files/1036742/63771556425.pdf
- https://site-1036824.mozfiles.com/files/1036824/gakugebifamidubisogoxop.pdf
- https://site-1037868.mozfiles.com/files/1037868/72915145797.pdf
- http://files.porterranchchiropractic.net/uploads/1/3/2/8/132814898/sukukuwusoposet.pdf
- http://kojibofi.chicagoforchicagoans.org/uploads/1/3/1/4/131408864/mozopidopu_kadunegum_pudoke_nubilop.pdf
- http://buxej.carolinamunozparra.com/uploads/1/3/2/6/132682233/fc676a8.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- files.mrwhitchermath.com
- files.insightsmanila.com
- buteta.suzannedemontignycounseling.com
- files.claphands.net
- cdn.shopify.com
- site-1039143.mozfiles.com
- site-1036742.mozfiles.com
- site-1036824.mozfiles.com
- site-1037868.mozfiles.com
- files.porterranchchiropractic.net
- kojibofi.chicagoforchicagoans.org
- buxej.carolinamunozparra.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report