MALICIOUS — basusutagutowewiz.pdf
MALICIOUS — basusutagutowewiz.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2b7781f043d669b45eced365a78ffcb7c0fc7efc90a7accd142bc82bd540cc0f - SHA-1:
de36fef70f92dccd7c8b60e7f6e9d17d6d96e49c - MD5:
a8d1cf93c10e14f621df242f493d27b9 - ssdeep:
768:3gGzpDCey4NzNsvA2hbg9pNaMvcLkEspPWOmlEXVqQWUsZBOU00Z+bMkK6PRFO74:QGFGeySH2C9pN8moOU0dbMt6JS7sP6k - TLSH:
T1E934AEF750A7DD8C7AC7AB436AEB255DA189DB892032A751998C672CC0BC7BD7E00440 - Submitted as: basusutagutowewiz.pdf
- File type: pdf · Size: 56649 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/bb42c4e8-91fe-404c-be81-a13fbca8aa48/xufopekegamiwobiza.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=investigacion%20de%20operaciones%20taha%20ejercicios%20resueltos, https://uploads.strikinglycdn.com/files/cde2cdf1-7c00-4eec-83b5-039146083df3/63474375981.pdf, https://uploads.strikinglycdn.com/files/bb42c4e8-91fe-404c-be81-a13fbca8aa48/xufopekegamiwobiza.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=investigacion%20de%20operaciones%20taha%20ejercicios%20resueltos
- https://uploads.strikinglycdn.com/files/cde2cdf1-7c00-4eec-83b5-039146083df3/63474375981.pdf
- https://uploads.strikinglycdn.com/files/bb42c4e8-91fe-404c-be81-a13fbca8aa48/xufopekegamiwobiza.pdf
- https://uploads.strikinglycdn.com/files/87139d3e-58a7-4c8b-8068-0f5d3c40d31d/mosujanilekanozaxut.pdf
- https://uploads.strikinglycdn.com/files/5db6d23d-d3eb-4d8d-8aca-e4ff4f5735f3/kuzikiwukaral.pdf
- https://vopevejefed.weebly.com/uploads/1/3/1/6/131606133/5f43dfd0.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/tolujimifiv.pdf
- https://dirigesibujov.weebly.com/uploads/1/3/0/9/130969991/jimutip.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/2697538.pdf
- https://cdn.shopify.com/s/files/1/0481/3206/3383/files/facebook_secret_video.pdf
- https://cdn.shopify.com/s/files/1/0434/5800/3096/files/62433195874.pdf
- https://cdn.shopify.com/s/files/1/0468/8366/8125/files/victor_frankenstein_quotes_about_science.pdf
- https://cdn.shopify.com/s/files/1/0483/6343/8243/files/jepodidiweditoru.pdf
- https://site-1039188.mozfiles.com/files/1039188/17440214802.pdf
- https://site-1038669.mozfiles.com/files/1038669/vapowilut.pdf
- https://site-1040766.mozfiles.com/files/1040766/87483873073.pdf
- https://site-1037261.mozfiles.com/files/1037261/77921460988.pdf
- https://cdn.shopify.com/s/files/1/0437/7057/7045/files/2601372044.pdf
- https://cdn.shopify.com/s/files/1/0483/6347/1001/files/jofutuxewotub.pdf
- https://cdn-cms.f-static.net/uploads/4366044/normal_5f870458bbffa.pdf
- https://cdn-cms.f-static.net/uploads/4366350/normal_5f877465b742b.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f8769f74b24a.pdf
- https://cdn-cms.f-static.net/uploads/4366381/normal_5f876cc4e1c9f.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- vopevejefed.weebly.com
- mojivimimujovo.weebly.com
- dirigesibujov.weebly.com
- dimaxafazeza.weebly.com
- cdn.shopify.com
- site-1039188.mozfiles.com
- site-1038669.mozfiles.com
- site-1040766.mozfiles.com
- site-1037261.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report