SUSPICIOUS — vorimalerisudizogap.pdf
SUSPICIOUS — vorimalerisudizogap.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c9d66e1a73865b51bbc8a8f4c03209a17a178d5953122de339fc486c5859cbb7 - SHA-1:
e73fc8d0c9aef0ca53c54b22ef51273102b9ff82 - MD5:
5282da00ef94a72b31a6ea1e5c072144 - ssdeep:
768:pgGzpDHp5I1/tGZHPAtyObHessERLyuJBAuyCY12AbJkmNSUXTz:KGF7pBA0k+squdB2NSUXTz - TLSH:
T15E329CF310A3ED4C798B6F439EA71199614E868C7037979049DCB22CD438AFD6F218A1 - Submitted as: vorimalerisudizogap.pdf
- File type: pdf · Size: 47370 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/9e1fac55-bf24-4584-b46d-fde92038e9df/39139934845.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=demande+d%2527une+attestation+de+travail+pdf, https://uploads.strikinglycdn.com/files/9e1fac55-bf24-4584-b46d-fde92038e9df/39139934845.pdf, https://uploads.strikinglycdn.com/files/97b5c3d0-4e61-42fb-8147-fd013d8be383/nukobabuzuk.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=demande+d%2527une+attestation+de+travail+pdf
- https://uploads.strikinglycdn.com/files/9e1fac55-bf24-4584-b46d-fde92038e9df/39139934845.pdf
- https://uploads.strikinglycdn.com/files/97b5c3d0-4e61-42fb-8147-fd013d8be383/nukobabuzuk.pdf
- https://uploads.strikinglycdn.com/files/e90e4414-9bda-4bc5-bd1a-2d6cf213767e/58957682969.pdf
- https://uploads.strikinglycdn.com/files/b3d5e10a-703d-430d-a707-3d33cb95636b/zipozixunewakipab.pdf
- https://uploads.strikinglycdn.com/files/f544a324-3dad-4912-b1c5-b2e630a3b17c/14722427174.pdf
- https://site-1041405.mozfiles.com/files/1041405/19365566264.pdf
- https://site-1036934.mozfiles.com/files/1036934/88107736194.pdf
- https://cdn-cms.f-static.net/uploads/4366360/normal_5f872b916cb89.pdf
- https://cdn-cms.f-static.net/uploads/4366007/normal_5f870ff831cac.pdf
- https://cdn-cms.f-static.net/uploads/4365660/normal_5f8728c115952.pdf
- https://cdn-cms.f-static.net/uploads/4366022/normal_5f870045c29fb.pdf
- https://cdn-cms.f-static.net/uploads/4366367/normal_5f87150552437.pdf
- https://uploads.strikinglycdn.com/files/d2dfd01c-b556-4d11-b043-e663a1705ead/23916165961.pdf
- https://uploads.strikinglycdn.com/files/a6b84054-0f6d-4fde-b55e-53fe126cbe02/kawaravebo.pdf
- https://uploads.strikinglycdn.com/files/d81b0b01-13ec-4f5a-bbf6-5c0b618fa0a5/8188575385.pdf
- https://uploads.strikinglycdn.com/files/23a584f4-19c3-4115-91e0-b1a91a3ca895/wajefadefobup.pdf
- https://uploads.strikinglycdn.com/files/9f8cc50c-48f5-41f2-9aad-0fc59bdf4bdc/94292531687.pdf
- https://uploads.strikinglycdn.com/files/fe55e8fd-0212-4cd2-b201-1a4e343768ab/62945025055.pdf
- https://uploads.strikinglycdn.com/files/807d5cd8-b9bf-4001-a6c2-bacf82eb6da8/47077053087.pdf
- https://uploads.strikinglycdn.com/files/b9a5cca4-9da5-4aaf-bebe-08f8aa81a553/fadojuvevug.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1041405.mozfiles.com
- site-1036934.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report