SUSPICIOUS — kuriwidupesejaro.pdf
SUSPICIOUS — kuriwidupesejaro.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (51/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3a8956cefc177870f49c90867c3672cb4cc424d8a4337b28b3a4f36e84c221c2 - SHA-1:
ad6897c484bb313413073a389489cb750a4aa48a - MD5:
0b3b1ab207306871ab2663f4ca2ab36f - ssdeep:
768:BgGzpDxpEVsB1awFciz4glrxY1SiuDQt2DoezJ9+cB:yGFVpE03M1SiuDeU3V9+cB - TLSH:
T107305CF300A7EC8C7A8FAF87BDB715A9644AD388612687504498272DC47C6FD7F10A61 - Submitted as: kuriwidupesejaro.pdf
- File type: pdf · Size: 37197 bytes
- Verdict: suspicious (51/100)
Detections (2 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 51/100 is the fusion of 3 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/68d94dfc-0bf2-4024-b662-9720fcb219de/43966274991.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=benim%20hocam%202019%20kpss%20matematik%20soru%20bankas%C4%B1%20pdf, https://uploads.strikinglycdn.com/files/68d94dfc-0bf2-4024-b662-9720fcb219de/43966274991.pdf, https://uploads.strikinglycdn.com/files/0f859774-25c7-4b67-be13-71f054bf5298/71527596919.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=benim%20hocam%202019%20kpss%20matematik%20soru%20bankas%C4%B1%20pdf
- https://uploads.strikinglycdn.com/files/68d94dfc-0bf2-4024-b662-9720fcb219de/43966274991.pdf
- https://uploads.strikinglycdn.com/files/0f859774-25c7-4b67-be13-71f054bf5298/71527596919.pdf
- https://uploads.strikinglycdn.com/files/f2184fdc-975a-406f-9d93-d1e9e72fca83/22287378287.pdf
- https://uploads.strikinglycdn.com/files/0d6e0ca8-41a4-42ea-ad35-d705b2423206/wugupijapeweromekex.pdf
- https://uploads.strikinglycdn.com/files/441cc4df-5ea5-4d84-ba79-0d1ce7a919f5/94095979940.pdf
- https://cdn.shopify.com/s/files/1/0433/0009/4112/files/how_many_electrons_can_each_p_orbital_hold.pdf
- https://uploads.strikinglycdn.com/files/6f168e73-ea70-4245-b44f-51742249f09c/pekekupi.pdf
- https://uploads.strikinglycdn.com/files/51c4394e-9f13-4eb3-8c75-4ff84508918a/nifek.pdf
- https://uploads.strikinglycdn.com/files/efd31a0b-8df2-478b-8f94-d98df4e32707/24209124863.pdf
- https://uploads.strikinglycdn.com/files/2db7f48a-a323-40f7-9b53-1f15dbe628b1/9411409021.pdf
- https://uploads.strikinglycdn.com/files/a0b4ae1f-1154-4068-84d2-d404d09472a4/85323563631.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/aa94aa7f99c.pdf
- https://dojulukasinu.weebly.com/uploads/1/3/0/7/130776790/voramudotunawupiloz.pdf
- https://fanavepuru.weebly.com/uploads/1/3/1/8/131871984/gipopodenuvet-viwarizu-xepigegububi.pdf
- https://kubupukadumu.weebly.com/uploads/1/3/1/3/131382740/5383047.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/goxarujemexogu_mosegozivi_fofuwad_kezobal.pdf
- https://cdn-cms.f-static.net/uploads/4366987/normal_5f877afcb61bd.pdf
- https://cdn-cms.f-static.net/uploads/4366043/normal_5f87a5046dfdf.pdf
- https://cdn-cms.f-static.net/uploads/4367310/normal_5f876e7399517.pdf
- https://cdn-cms.f-static.net/uploads/4366399/normal_5f8782fdbb2d0.pdf
- https://cdn-cms.f-static.net/uploads/4365635/normal_5f8717745835e.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- gimejexoxixaza.weebly.com
- dojulukasinu.weebly.com
- fanavepuru.weebly.com
- kubupukadumu.weebly.com
- wepugimi.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report