SUSPICIOUS — jexiledekomira-sexivab-fosewafuvusazet-turasenezesaxa.pdf
SUSPICIOUS — jexiledekomira-sexivab-fosewafuvusazet-turasenezesaxa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
eff564ebe72f942560ecfc720cf66d33046041fbbbe63adcfcc259d1a9dd9a5c - SHA-1:
c3f7a07229d7e594157650c30903357625997b74 - MD5:
01a539e32e5f01a90291caa8a41e3e56 - ssdeep:
768:+gGzpDLpUheF9VHC22ODrcBKn813LQwlOtv7u3v8wvXRv7stVkla105YK6D:7GFfp+ROovDXRv7sUN5P6D - TLSH:
T1DB327EF31093EC4D3ACBAF03EAEB119D541AD24D613A96A1518C376DD47C6EE7E00A21 - Submitted as: jexiledekomira-sexivab-fosewafuvusazet-turasenezesaxa.pdf
- File type: pdf · Size: 44182 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/a03a0f8d-409b-454e-87f0-757fe60e789e/54001178057.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=bavinck%20reformed%20dogmatics%20pdf, https://uploads.strikinglycdn.com/files/a03a0f8d-409b-454e-87f0-757fe60e789e/54001178057.pdf, https://uploads.strikinglycdn.com/files/9892e36e-6d80-4a40-9fe1-c549ba9c375b/zaweruvidew.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=bavinck%20reformed%20dogmatics%20pdf
- https://uploads.strikinglycdn.com/files/a03a0f8d-409b-454e-87f0-757fe60e789e/54001178057.pdf
- https://uploads.strikinglycdn.com/files/9892e36e-6d80-4a40-9fe1-c549ba9c375b/zaweruvidew.pdf
- https://uploads.strikinglycdn.com/files/d333ce2c-dcd3-42a8-b97f-014662dee018/25155851944.pdf
- https://cdn-cms.f-static.net/uploads/4370266/normal_5f89b13d7b7c8.pdf
- https://cdn-cms.f-static.net/uploads/4373508/normal_5f8a185a906b2.pdf
- https://cdn-cms.f-static.net/uploads/4370059/normal_5f884a8156e8e.pdf
- https://cdn.shopify.com/s/files/1/0497/6050/1921/files/zubesos.pdf
- https://cdn.shopify.com/s/files/1/0493/4906/6911/files/31993844585.pdf
- https://cdn.shopify.com/s/files/1/0480/9824/6820/files/pittsburgh_movie_theater_with_recliners.pdf
- https://uploads.strikinglycdn.com/files/928cf608-9982-477b-9687-dd7b3fed2e63/fopekutusunekiv.pdf
- https://uploads.strikinglycdn.com/files/06f00df8-1aba-4529-8ec5-1f2186c678f2/90545162893.pdf
- https://uploads.strikinglycdn.com/files/a53877df-8c62-40c9-8d1c-80dc3c4b1cb1/renepijavodumeji.pdf
- https://uploads.strikinglycdn.com/files/780c398e-15f2-452c-8808-b82331594343/89635754093.pdf
- https://uploads.strikinglycdn.com/files/ae76aa46-5b14-4c03-896c-2bd92f55f875/fodat.pdf
- https://cdn.shopify.com/s/files/1/0500/5957/5482/files/73746166644.pdf
- https://cdn.shopify.com/s/files/1/0437/6880/7586/files/cjbat_study_guide_2017.pdf
- https://cdn.shopify.com/s/files/1/0440/6142/5814/files/weed_eater_lawn_mower_22_inch.pdf
- https://cdn.shopify.com/s/files/1/0483/7762/6784/files/discord_slow_mode_mobile.pdf
- https://cdn.shopify.com/s/files/1/0480/9074/2948/files/75900623571.pdf
- https://cdn.shopify.com/s/files/1/0437/0792/4635/files/wilton_fire_dept_nh.pdf
- https://cdn.shopify.com/s/files/1/0433/8886/2614/files/glendale_az_library_polaris.pdf
- https://cdn.shopify.com/s/files/1/0429/8306/3715/files/nipufogarujarixozupebo.pdf
- https://cdn.shopify.com/s/files/1/0502/5307/0509/files/gupewadarax.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report