SUSPICIOUS — jujogusulazibisu.pdf
SUSPICIOUS — jujogusulazibisu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ecc1d7fd607950ab10b1e5896d48a34524917abc0be3302a20df40de26dd1251 - SHA-1:
984d19f2eead932ff736521a94b67c49fb8d1909 - MD5:
57a0fbd31bbf654eff7a1c1b374fb9f8 - ssdeep:
768:2gGzpDan2EVuUiye8W/rpNXjzftI1pxUQFzvmv3+EOFjWxCp6QOovVIta:jGFW2O7FjW/rfz7yX9xmv3+BFqCp+ovl - TLSH:
T1DF33A0F311ABDCCC768EAB076DB61099A54BC28961379B90148C7B3CC8BC5FD6E10A50 - Submitted as: jujogusulazibisu.pdf
- File type: pdf · Size: 48428 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://lituv.stjberchmans.com/uploads/1/3/0/9/130969505/3964071.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=descargar+sistema+operativo+windows+7+64+bits+mega, http://lituv.stjberchmans.com/uploads/1/3/0/9/130969505/3964071.pdf, http://veleludol.flashforge.com.hk/uploads/1/3/1/3/131381464/163669.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=descargar+sistema+operativo+windows+7+64+bits+mega
- http://lituv.stjberchmans.com/uploads/1/3/0/9/130969505/3964071.pdf
- http://veleludol.flashforge.com.hk/uploads/1/3/1/3/131381464/163669.pdf
- http://files.bamboo.gs/uploads/1/3/1/6/131606128/pewub_vegatiwevip_rulumag_besokade.pdf
- http://files.changemakerllp.co.uk/uploads/1/3/0/7/130775108/kesalejom.pdf
- http://files.trythatwine.com/uploads/1/3/2/3/132302824/0ecac2.pdf
- https://uploads.strikinglycdn.com/files/fad2f94f-2558-4067-84ee-df0c49657277/52044064847.pdf
- https://uploads.strikinglycdn.com/files/eeca4a47-f691-4885-bc40-be53b5eaf35d/bidukev.pdf
- https://uploads.strikinglycdn.com/files/8f119fc9-1570-4f04-8941-8d9e61a3183a/64389089621.pdf
- https://uploads.strikinglycdn.com/files/9a9db8ca-6035-4d55-920d-41f213254ab1/bevowifafopige.pdf
- https://uploads.strikinglycdn.com/files/964e15cd-b8c0-466c-a9ae-57720e448317/garonawidorobivur.pdf
- https://site-1040881.mozfiles.com/files/1040881/38638388258.pdf
- https://site-1041608.mozfiles.com/files/1041608/zowanenopar.pdf
- https://site-1039787.mozfiles.com/files/1039787/fevilamirupovakixa.pdf
- https://site-1040325.mozfiles.com/files/1040325/wadisebu.pdf
- https://site-1036636.mozfiles.com/files/1036636/66729938447.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- lituv.stjberchmans.com
- veleludol.flashforge.com.hk
- files.changemakerllp.co.uk
- files.trythatwine.com
- uploads.strikinglycdn.com
- site-1040881.mozfiles.com
- site-1041608.mozfiles.com
- site-1039787.mozfiles.com
- site-1040325.mozfiles.com
- site-1036636.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
- files.bamboo.gs
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report