SUSPICIOUS — vatogolulaxo.pdf
SUSPICIOUS — vatogolulaxo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c93752c1e0f264e48eae0a677fc205c3b0c3ff0a682cc9672942d7948517f075 - SHA-1:
ca796be2b90bef87005a7a10d4bb9f2a508b9ecc - MD5:
5c7c31bd31124fd3f2197453fb7775af - ssdeep:
1536:6GFCefoe5bUCnPVycgTL3pP47LB1tFtLxU4eTq+epglI:jFCefzPOL3pEv7R+4eTTOb - TLSH:
T1FA37AEF351ABCDCC36C7AB1369EA1418A54ADB487123DBA04488B76CC4BC6BD7F10A51 - Submitted as: vatogolulaxo.pdf
- File type: pdf · Size: 73597 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/28dde39b-8acf-44fd-88f6-8bc8897a17e8/94231229129.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=pokemon+sun+eevee+evolution+guide, https://uploads.strikinglycdn.com/files/28dde39b-8acf-44fd-88f6-8bc8897a17e8/94231229129.pdf, https://uploads.strikinglycdn.com/files/ee65d48e-0f12-461a-a2b0-a28962fc32e4/14988069309.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=pokemon+sun+eevee+evolution+guide
- https://uploads.strikinglycdn.com/files/28dde39b-8acf-44fd-88f6-8bc8897a17e8/94231229129.pdf
- https://uploads.strikinglycdn.com/files/ee65d48e-0f12-461a-a2b0-a28962fc32e4/14988069309.pdf
- https://uploads.strikinglycdn.com/files/2800d14a-fc5d-4766-829c-aa2791721a24/9543933685.pdf
- https://cdn-cms.f-static.net/uploads/4366406/normal_5f872a964558d.pdf
- https://cdn-cms.f-static.net/uploads/4366659/normal_5f871c229593b.pdf
- https://cdn-cms.f-static.net/uploads/4366340/normal_5f87267b3f070.pdf
- https://cdn-cms.f-static.net/uploads/4366029/normal_5f86fc3d40c2b.pdf
- https://cdn-cms.f-static.net/uploads/4366029/normal_5f870f69743b9.pdf
- https://site-1039752.mozfiles.com/files/1039752/vekoloxofi.pdf
- https://site-1039380.mozfiles.com/files/1039380/letibabu.pdf
- https://site-1042843.mozfiles.com/files/1042843/pomofowidizaturololuni.pdf
- https://site-1042607.mozfiles.com/files/1042607/45960486471.pdf
- https://uploads.strikinglycdn.com/files/bb5791e0-08e0-4648-adfe-c22b2b2f7793/jilefodotibunuzojazano.pdf
- https://uploads.strikinglycdn.com/files/1a243903-ee0e-4edb-b9d3-623229f2a639/92322210318.pdf
- https://uploads.strikinglycdn.com/files/0e560c63-c4da-49cd-9396-6f275d5ebc2d/gowafekefolopunebekotonu.pdf
- https://uploads.strikinglycdn.com/files/382f46e8-3047-4509-994d-ed447770464f/wulixirazadejuwewanepixe.pdf
- https://uploads.strikinglycdn.com/files/7edd93e5-a15e-4b7e-9778-8d8b105d4c38/29692447973.pdf
- https://cdn.shopify.com/s/files/1/0266/9176/4414/files/fozopajebajakazanonomawe.pdf
- https://cdn.shopify.com/s/files/1/0429/0124/2015/files/fesobu.pdf
- https://cdn.shopify.com/s/files/1/0434/0681/9493/files/gutuzerokuzekub.pdf
- https://cdn.shopify.com/s/files/1/0498/5998/5565/files/bigopudizazovigijuk.pdf
- https://cdn.shopify.com/s/files/1/0429/6297/6921/files/clicker_heroes_hacked_unblocked_77.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1039752.mozfiles.com
- site-1039380.mozfiles.com
- site-1042843.mozfiles.com
- site-1042607.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report