SUSPICIOUS — bisafexesel.pdf
SUSPICIOUS — bisafexesel.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
218b245433a14b23e3116a1371af09832b139bad44eae9e97354b29f5e7ac383 - SHA-1:
6a19f2812b12c7e860c3cfdf7122e450462cdd04 - MD5:
7c3cc0a3a70d85b1b3f6ca226f7c13f2 - ssdeep:
768:QgGzpDxpxd5MNDx3+rIUxVPNumGf/noEaHo+FcMY0/+9QCh9+pW9z:9GFFppgcrRo+SMY++9L96W9z - TLSH:
T15D329DF714D7ED8CB986AF039CEB10652549C78CB1239A60999C773CD8BC6BD6E10920 - Submitted as: bisafexesel.pdf
- File type: pdf · Size: 43526 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://fimosezit.weebly.com/uploads/1/3/0/7/130775491/luraxo_pifesejix_dugelusegi_vuwimezokawel.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=outlander%20sport%20repair%20manual, https://uploads.strikinglycdn.com/files/f31069fb-726d-4519-9b11-6c409f646040/dowavemaxorobalisilurur.pdf, https://uploads.strikinglycdn.com/files/cf5c3ff6-5da3-4b4e-94c0-3da86e683525/30005179486.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=outlander%20sport%20repair%20manual
- https://uploads.strikinglycdn.com/files/f31069fb-726d-4519-9b11-6c409f646040/dowavemaxorobalisilurur.pdf
- https://uploads.strikinglycdn.com/files/cf5c3ff6-5da3-4b4e-94c0-3da86e683525/30005179486.pdf
- https://uploads.strikinglycdn.com/files/00436ea9-5cfc-4971-be45-84ce24fe278d/11913058370.pdf
- https://cdn.shopify.com/s/files/1/0484/9929/4369/files/75943129417.pdf
- https://cdn.shopify.com/s/files/1/0266/8114/7582/files/fudulixigexonusizenilabup.pdf
- https://cdn.shopify.com/s/files/1/0484/4162/2682/files/wikegipudakunudij.pdf
- https://cdn.shopify.com/s/files/1/0478/1834/2559/files/xojugijuvazexara.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/kezupukono.pdf
- https://fimosezit.weebly.com/uploads/1/3/0/7/130775491/luraxo_pifesejix_dugelusegi_vuwimezokawel.pdf
- https://fulipevaxavu.weebly.com/uploads/1/3/2/6/132695351/c60283b4bf140f.pdf
- https://fanavepuru.weebly.com/uploads/1/3/1/8/131871984/vadow-werotofegele-dirowe.pdf
- https://cdn-cms.f-static.net/uploads/4368248/normal_5f8857413821b.pdf
- https://cdn-cms.f-static.net/uploads/4365549/normal_5f86fd81d5f4e.pdf
- https://uploads.strikinglycdn.com/files/f949951f-759f-4999-96de-00b5d122aa9b/fikavinefevin.pdf
- https://uploads.strikinglycdn.com/files/8d04faff-3284-4b18-9c69-29571ef92add/vovinobizixujusovig.pdf
- https://viweposedijul.weebly.com/uploads/1/3/1/0/131070314/lexibefe.pdf
- https://vimiwegom.weebly.com/uploads/1/3/0/7/130775837/b8a7b22de405.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/1109957.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- bedizegoresupa.weebly.com
- fimosezit.weebly.com
- fulipevaxavu.weebly.com
- fanavepuru.weebly.com
- cdn-cms.f-static.net
- viweposedijul.weebly.com
- vimiwegom.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report