SUSPICIOUS — bazegelipuwisarezatu.pdf
SUSPICIOUS — bazegelipuwisarezatu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
007f8f862be92d42c24676bc60f4524b03174756aded50972ff2be24cfb365a3 - SHA-1:
ffbd10602d52813a42f240f2bbf9952a8246affa - MD5:
b5b6edd833132e21a0c47a59b1a66343 - ssdeep:
768:jgGzpDi1Un/PYqcIRTSlT9/TCjB/k9XI4eck7/mBOVymyv/:cGFm1QerbeWI4eT+wy/ - TLSH:
T1A232AEF30593ED9C6AC7AB07ADA720694049C2896233D3245C88B72DD4BC5FDBF10962 - Submitted as: bazegelipuwisarezatu.pdf
- File type: pdf · Size: 43563 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/5dae8539-427d-4408-9067-2e709ee53d4d/xuwuzubojilafefaxibok.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=alternative+investments+caia+level+i%2528+wiley+finance+pdf, https://site-1036909.mozfiles.com/files/1036909/20453468316.pdf, https://site-1036649.mozfiles.com/files/1036649/kuladupol.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=alternative+investments+caia+level+i%2528+wiley+finance+pdf
- https://site-1036909.mozfiles.com/files/1036909/20453468316.pdf
- https://site-1036649.mozfiles.com/files/1036649/kuladupol.pdf
- https://site-1036956.mozfiles.com/files/1036956/83281172050.pdf
- https://site-1037163.mozfiles.com/files/1037163/21279648006.pdf
- https://site-1037224.mozfiles.com/files/1037224/rixusojuzis.pdf
- https://site-1036730.mozfiles.com/files/1036730/xawipesoludepafap.pdf
- https://site-1036962.mozfiles.com/files/1036962/bunavidositoliji.pdf
- https://uploads.strikinglycdn.com/files/7ebd0a64-1afe-401b-85d8-8370c410994f/fowoxuwojiki.pdf
- https://uploads.strikinglycdn.com/files/5dae8539-427d-4408-9067-2e709ee53d4d/xuwuzubojilafefaxibok.pdf
- https://uploads.strikinglycdn.com/files/ffd8e4c5-9e55-4c16-b105-4836b9114b8a/vefebeli.pdf
- https://uploads.strikinglycdn.com/files/a28e9400-1d75-43a0-959a-87b1240e8eb3/21209384310.pdf
- https://cdn.shopify.com/s/files/1/0434/8359/4909/files/astm_a572_standard.pdf
- https://cdn.shopify.com/s/files/1/0431/2032/8864/files/pipoguvenekepiji.pdf
- https://cdn.shopify.com/s/files/1/0482/6765/7371/files/94749438790.pdf
- https://cdn.shopify.com/s/files/1/0428/9835/8432/files/zemeletitofugawekabol.pdf
- https://cdn.shopify.com/s/files/1/0484/8556/4571/files/30013118151.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1036909.mozfiles.com
- site-1036649.mozfiles.com
- site-1036956.mozfiles.com
- site-1037163.mozfiles.com
- site-1037224.mozfiles.com
- site-1036730.mozfiles.com
- site-1036962.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report