SUSPICIOUS — midalowuso.pdf
SUSPICIOUS — midalowuso.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
eccd0bb7422ede01e4b3f0ca9637ea735a14eeef6e0427c7324474867aeef755 - SHA-1:
3e2a8cc3398497f005246d864178c77cd47a8027 - MD5:
2f125b48392c6d2ee6dd81f70a9aa4ab - ssdeep:
768:8gGzpDPpXNjCZTGXcxaBuf4bHlgSKbeJNXjBxhBoNizB6iZlMUFY+TExcqu+o:ZGFDpnU0TlJUeJNzBHiiBxX6cqvo - TLSH:
T1F232AEF750ABDC8C6A869753ADFA206565C5D3892133E7A458D87B2CC0BCAFD6E00431 - Submitted as: midalowuso.pdf
- File type: pdf · Size: 47240 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://toboxokus.shcslibrary.org/uploads/1/3/0/7/130738615/gazujanabak_podopasula.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=maja+de+santa+maria+wikipedia, https://cdn.shopify.com/s/files/1/0484/5853/0966/files/50715757976.pdf, https://cdn.shopify.com/s/files/1/0481/2623/0679/files/wired_magazine_style_guide.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=maja+de+santa+maria+wikipedia
- https://cdn.shopify.com/s/files/1/0484/5853/0966/files/50715757976.pdf
- https://cdn.shopify.com/s/files/1/0481/2623/0679/files/wired_magazine_style_guide.pdf
- https://cdn.shopify.com/s/files/1/0436/1335/6194/files/25657123525.pdf
- http://bowugatat.paseco.org/uploads/1/3/2/6/132682076/3489763.pdf
- http://luwijop.prosphatos.com/uploads/1/3/1/3/131384081/vokuronipaxana.pdf
- http://files.kokenbijmijntante.nl/uploads/1/3/1/3/131383681/ad9ba5a9a.pdf
- http://toboxokus.shcslibrary.org/uploads/1/3/0/7/130738615/gazujanabak_podopasula.pdf
- http://xejujuza.mililanisoccer.com/uploads/1/3/1/1/131163729/2391c62761963d.pdf
- https://site-1041173.mozfiles.com/files/1041173/zosunapizumubepaj.pdf
- https://site-1038649.mozfiles.com/files/1038649/fikegulakaba.pdf
- https://site-1048260.mozfiles.com/files/1048260/17030233755.pdf
- https://site-1040665.mozfiles.com/files/1040665/87829801402.pdf
- https://site-1042734.mozfiles.com/files/1042734/81171009219.pdf
- https://uploads.strikinglycdn.com/files/4d39e3a2-60c1-42bb-9798-2ddd9fc0778b/rojujawopuzo.pdf
- https://uploads.strikinglycdn.com/files/f0efbe85-7fe3-40ef-b40a-64b9545884d2/gevepililidapipijebiwusi.pdf
- https://uploads.strikinglycdn.com/files/43e9eff5-07d3-44f3-a9a2-9cc1f0afc3d7/55797281262.pdf
- https://uploads.strikinglycdn.com/files/a4c0b501-7780-4f19-b4f7-3957ec73c0ba/dafugem.pdf
- https://uploads.strikinglycdn.com/files/36cf2e73-4bd0-4daa-9070-72f4f439fb81/92629876194.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- bowugatat.paseco.org
- luwijop.prosphatos.com
- files.kokenbijmijntante.nl
- toboxokus.shcslibrary.org
- xejujuza.mililanisoccer.com
- site-1041173.mozfiles.com
- site-1038649.mozfiles.com
- site-1048260.mozfiles.com
- site-1040665.mozfiles.com
- site-1042734.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report