SUSPICIOUS — noxaliw-pidiga.pdf
SUSPICIOUS — noxaliw-pidiga.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
096f2cf20037c195537e40578010a1f1175ec7346e228b89977b6fa8de770f0e - SHA-1:
7af17bddb8bace882544e2f3de23822b5be0e9f8 - MD5:
bc289c66d6960af1f11118ad77f325d9 - ssdeep:
768:lgGzpDAp5XAKqWNIAxgp6+QVu8SoVFdZZ9pDvLKzoyufj1VQdATlbRc0Bmwh6spA:2GFUpW0FdZZ9pDTwoyWuA5dLBzh6sHVw - TLSH:
T1B933ADF350D7DC4C7B8AEB03ADA71526614AC7C8B132D75089883A2DC5BC6FE6E10961 - Submitted as: noxaliw-pidiga.pdf
- File type: pdf · Size: 48713 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://pudukodup.weebly.com/uploads/1/3/1/4/131407572/8603559.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=gacha%20life%20full%20version%20download%20fre, https://cdn.shopify.com/s/files/1/0501/0771/1653/files/saluyot_plant_in_english.pdf, https://cdn.shopify.com/s/files/1/0492/2658/0124/files/87400600736.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=gacha%20life%20full%20version%20download%20fre
- https://cdn.shopify.com/s/files/1/0501/0771/1653/files/saluyot_plant_in_english.pdf
- https://cdn.shopify.com/s/files/1/0492/2658/0124/files/87400600736.pdf
- https://cdn.shopify.com/s/files/1/0439/1731/2152/files/wasekasanaremizetik.pdf
- https://cdn.shopify.com/s/files/1/0498/1702/6715/files/7_day_sugar_detox_guide.pdf
- https://cdn-cms.f-static.net/uploads/4366956/normal_5f8b40c1d27f6.pdf
- https://cdn-cms.f-static.net/uploads/4368752/normal_5f8781f7ce0ed.pdf
- https://cdn-cms.f-static.net/uploads/4374369/normal_5f8b0f7a4b0ae.pdf
- https://cdn-cms.f-static.net/uploads/4374682/normal_5f89cdc548fb2.pdf
- https://pudukodup.weebly.com/uploads/1/3/1/4/131407572/8603559.pdf
- https://gewosawoma.weebly.com/uploads/1/3/0/7/130739201/sivesosogimiwisav.pdf
- https://jiwepurojal.weebly.com/uploads/1/3/0/7/130775762/5397186.pdf
- https://riwisasivituw.weebly.com/uploads/1/3/1/0/131070703/mosovexo.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/09b03b.pdf
- https://cdn.shopify.com/s/files/1/0439/4372/3163/files/97614194159.pdf
- https://cdn.shopify.com/s/files/1/0266/9474/6288/files/nabimuwox.pdf
- https://cdn.shopify.com/s/files/1/0433/4305/2953/files/23512230726.pdf
- https://cdn.shopify.com/s/files/1/0435/3071/5288/files/31332363271.pdf
- https://cdn.shopify.com/s/files/1/0266/9241/9757/files/wool_winter_coats.pdf
- https://uploads.strikinglycdn.com/files/ed206529-3244-425d-ae87-923ddb708700/14530817398.pdf
- https://uploads.strikinglycdn.com/files/a1dd8867-5b78-4abd-b137-104f487e083e/53267055684.pdf
- https://uploads.strikinglycdn.com/files/04070861-6e39-4c88-92f9-016dadd19939/zigaduzanunawido.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- pudukodup.weebly.com
- gewosawoma.weebly.com
- jiwepurojal.weebly.com
- riwisasivituw.weebly.com
- jatorogerujew.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report