SUSPICIOUS — niborag-kiguzotefafire.pdf
SUSPICIOUS — niborag-kiguzotefafire.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
10789c381b89797b2afab413cf7475aaf0608460108a164bb20d9f06fd7c419a - SHA-1:
d4a6d555243bcf8650a883b1d43e406bf75d2e19 - MD5:
5281a42fe4ddd98aa970d1426da12428 - ssdeep:
768:tgGzpDppiihPFEAP0V1ZKSyOT9nd+HTnSNRwbWK0xrqR0ejngjSP:OGF1p9tHPM1Z5M7SDwbWK0xuR0ejngjO - TLSH:
T142328DF310A7ED4C7A8FAB93ACA61199A44AC74C7133979044D8B72CC4BC5BE6F11A50 - Submitted as: niborag-kiguzotefafire.pdf
- File type: pdf · Size: 43674 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/e573c6bd-a3dd-45be-b4ad-12332e2e0635/36034618764.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=formule%20de%20politesse%20mail%20professeur, https://uploads.strikinglycdn.com/files/9f15cb3e-7c62-43c6-995e-c2de7349b138/2617572935.pdf, https://uploads.strikinglycdn.com/files/bf2049f1-77dd-49a3-ad0b-ef0a01c46dcc/jojikogeg.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=formule%20de%20politesse%20mail%20professeur
- https://uploads.strikinglycdn.com/files/9f15cb3e-7c62-43c6-995e-c2de7349b138/2617572935.pdf
- https://uploads.strikinglycdn.com/files/bf2049f1-77dd-49a3-ad0b-ef0a01c46dcc/jojikogeg.pdf
- https://uploads.strikinglycdn.com/files/e573c6bd-a3dd-45be-b4ad-12332e2e0635/36034618764.pdf
- https://uploads.strikinglycdn.com/files/3c5153e2-c406-432b-8a61-4d3ed330a403/22753838385.pdf
- https://uploads.strikinglycdn.com/files/042295e2-6518-497a-8c09-7914ffad854f/warebigewopunonu.pdf
- https://uploads.strikinglycdn.com/files/8e8d7272-3a03-457c-8db2-00ef248a9c67/rafafatusuvagorudazu.pdf
- https://uploads.strikinglycdn.com/files/b4e9cbcf-52dc-4b2c-a1aa-47edb177bd23/24954759366.pdf
- https://site-1036731.mozfiles.com/files/1036731/rokinenefijekefutidipato.pdf
- https://site-1043459.mozfiles.com/files/1043459/64727242413.pdf
- https://site-1039163.mozfiles.com/files/1039163/95816187270.pdf
- https://cdn-cms.f-static.net/uploads/4366385/normal_5f87bdc317a56.pdf
- https://cdn-cms.f-static.net/uploads/4365546/normal_5f8783d1e7518.pdf
- https://cdn-cms.f-static.net/uploads/4366034/normal_5f87490e2f00f.pdf
- https://cdn-cms.f-static.net/uploads/4367642/normal_5f883ea81649c.pdf
- https://cdn-cms.f-static.net/uploads/4367013/normal_5f8863d3ad40c.pdf
- https://uploads.strikinglycdn.com/files/68c89b1c-9bae-4a7d-9d65-20ceaf5d75cd/13297280243.pdf
- https://uploads.strikinglycdn.com/files/5f971a40-423b-486b-ac1f-24bb9916ea6c/56354473564.pdf
- https://uploads.strikinglycdn.com/files/c9a6dab7-a0e4-4764-933a-6ef75f0934b9/pobisavubogopaz.pdf
- https://uploads.strikinglycdn.com/files/50690aeb-9f92-4f93-ad91-11985589dbcc/60928676052.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1036731.mozfiles.com
- site-1043459.mozfiles.com
- site-1039163.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report