SUSPICIOUS — dunosezofa-bavodosomisigas.pdf
SUSPICIOUS — dunosezofa-bavodosomisigas.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
33ac3e018114501ed34efbac673f8f48ab7bd91fbd5537992d5760440c397138 - SHA-1:
f5581d13256cfc11c5ffaefc73ef1bf7acfdf08b - MD5:
e48e95930c1303577d0b0c39d3929b3f - ssdeep:
768:ZgGzpDzpIFBbZ3k0oK+Gv+WCbaPs9OIS6EzVTjlJskaOl0tWhEIB3xuptS2e:aGFPpIF3bIiZocKw3YzS2e - TLSH:
T1F632ADF31147ED8C3A87AF43AEAB115A5149D6883226E79009CC772CC87CAFD6F50861 - Submitted as: dunosezofa-bavodosomisigas.pdf
- File type: pdf · Size: 45160 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://dozasasakebo.weebly.com/uploads/1/3/1/1/131164234/7519535.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=tu%20t, https://dirigesibujov.weebly.com/uploads/1/3/0/9/130969991/9044166.pdf, https://dozasasakebo.weebly.com/uploads/1/3/1/1/131164234/7519535.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=tu%20t
- https://dirigesibujov.weebly.com/uploads/1/3/0/9/130969991/9044166.pdf
- https://dozasasakebo.weebly.com/uploads/1/3/1/1/131164234/7519535.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/9a128bc.pdf
- https://riwisasivituw.weebly.com/uploads/1/3/1/0/131070703/f55bf4143a.pdf
- https://cdn.shopify.com/s/files/1/0432/4956/5853/files/kissing_bug_florida_symptoms.pdf
- https://cdn.shopify.com/s/files/1/0434/9925/8022/files/perpendicular_bisector_through_a_point_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0479/2906/5639/files/pentax_67_owners_manual.pdf
- https://cdn.shopify.com/s/files/1/0501/4539/4858/files/baxi_megaflo_24kw_system_boiler_manual.pdf
- https://kivuligob.weebly.com/uploads/1/3/0/8/130874143/vutumamefome.pdf
- https://rezizeme.weebly.com/uploads/1/3/0/7/130775554/gekinafataluji.pdf
- https://cdn.shopify.com/s/files/1/0477/6414/4284/files/leeco_le_s3_x626_battery_replacement.pdf
- https://cdn.shopify.com/s/files/1/0437/9272/8226/files/sqoop_2_user_guide.pdf
- https://uploads.strikinglycdn.com/files/61ec25ed-0485-40ff-b722-df633e704e7c/sakoten.pdf
- https://uploads.strikinglycdn.com/files/0a4cea31-3ba6-4bb0-b6f0-d1790f298e05/3574116294.pdf
- https://uploads.strikinglycdn.com/files/a073c547-831a-42cb-bba0-c5802526ea5a/57708503762.pdf
- https://cdn.shopify.com/s/files/1/0432/2269/6098/files/wulaxidekuwisitiwulad.pdf
- https://cdn.shopify.com/s/files/1/0431/7881/9735/files/mapquest_classic_driving_directions.pdf
- https://cdn.shopify.com/s/files/1/0485/0473/3857/files/45984254565.pdf
- https://cdn.shopify.com/s/files/1/0496/6626/1141/files/xitabaxepopudileda.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- dirigesibujov.weebly.com
- dozasasakebo.weebly.com
- dutitujazekap.weebly.com
- riwisasivituw.weebly.com
- cdn.shopify.com
- kivuligob.weebly.com
- rezizeme.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report