SUSPICIOUS — gilavuge.pdf
SUSPICIOUS — gilavuge.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
dbcb593e8055b07e236824a907b334c50cd485ef4fa27cd568aea16bef052fec - SHA-1:
06fc99a85508b2cae692ebba87815346e1621358 - MD5:
9a7b7596612060ec439eea035e03b433 - ssdeep:
768:pZgGzpDXjRPa87huoMFc4d85XQBNdQeD6yy/x/w6RClwzwxwhd:AGFLF8Xd8NCcck66RClwzewhd - TLSH:
T14E318DF3049BDCCC7A86AB43AEFB1559214AC7883172DBA048C87B2CC47C67D6E51960 - Submitted as: gilavuge.pdf
- File type: pdf · Size: 42736 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/2ac46fcf-94f7-4e8f-aea8-854c0b15a03a/18879205644.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=houghton+mifflin+english+workbook+plus+grade+7+answer+key, http://files.theedgesalontxk.com/uploads/1/3/1/3/131398573/mekuvet_nanusinibulinid.pdf, http://files.teamrusscher.com/uploads/1/3/0/8/130874233/zogubolonagug_bimewote_tabumudig.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=houghton+mifflin+english+workbook+plus+grade+7+answer+key
- http://files.theedgesalontxk.com/uploads/1/3/1/3/131398573/mekuvet_nanusinibulinid.pdf
- http://files.teamrusscher.com/uploads/1/3/0/8/130874233/zogubolonagug_bimewote_tabumudig.pdf
- http://files.deutscherplatz.org/uploads/1/3/0/7/130776176/9293001.pdf
- http://files.bamyield.org/uploads/1/3/1/8/131856050/0a5d91.pdf
- http://files.susanparrpoetry.com/uploads/1/3/0/7/130775982/2397056.pdf
- https://uploads.strikinglycdn.com/files/2ac46fcf-94f7-4e8f-aea8-854c0b15a03a/18879205644.pdf
- https://uploads.strikinglycdn.com/files/8a0be5af-42fd-4a38-964b-b7a51d4d1281/92341583850.pdf
- https://uploads.strikinglycdn.com/files/db971f39-da34-4ec6-b002-115d3f6ac42a/77144183137.pdf
- https://cdn.shopify.com/s/files/1/0440/6257/2696/files/richmond_electric_water_heater_manual.pdf
- https://cdn.shopify.com/s/files/1/0483/3607/6953/files/how_we_think_john_dewey.pdf
- https://cdn.shopify.com/s/files/1/0440/0241/0654/files/puvaretazidapej.pdf
- https://cdn.shopify.com/s/files/1/0484/5243/6118/files/60034622886.pdf
- https://cdn.shopify.com/s/files/1/0433/0464/8859/files/ponusupevebewewumegewude.pdf
- https://uploads.strikinglycdn.com/files/fe78b916-22f4-462d-bab0-a2109295348c/38326466327.pdf
- https://uploads.strikinglycdn.com/files/5d2c688c-a728-47df-bbde-68a61b88cfad/tiwiv.pdf
- https://uploads.strikinglycdn.com/files/3ac48d0a-1710-43bb-aadc-98b4bf0a66fe/dijexalujur.pdf
- https://uploads.strikinglycdn.com/files/2c2d0c60-a302-4acc-aabd-53affb55eb93/xawufowewetinujup.pdf
- https://uploads.strikinglycdn.com/files/515e3490-981a-408b-9323-b53b1a3ae575/tefidogoloxori.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- files.theedgesalontxk.com
- files.teamrusscher.com
- files.deutscherplatz.org
- files.bamyield.org
- files.susanparrpoetry.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report