SUSPICIOUS — mabizige.pdf
SUSPICIOUS — mabizige.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3ab400d1628fb172a973963837d42ec5af7b7e9e8cf9372eea653b401a3e4052 - SHA-1:
fe594e9648f92fee020355d0e705a75dab9ad55b - MD5:
17313df8c0df6bb1a79773559c168a25 - ssdeep:
768:dgGzpDUpOtN82k2H+kFeqQaxzWVvQetgyXMNL1dQ/d6R3hvM:eGFgpOBeOyXi1d88R3hvM - TLSH:
T125328DF35097EC4C7B8BAB436DEB106A6589C3486137D7A05488776CD4BCAAE6E50C20 - Submitted as: mabizige.pdf
- File type: pdf · Size: 43304 bytes
- Verdict: suspicious (58/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/a7991a7c-0368-406b-b33d-2ae34669edbd/japozalavasefutepiruzavoj.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=internet%20cafe%20simulator%20apk%20indir, https://cdn.shopify.com/s/files/1/0493/7534/6847/files/download_m_tix_apk_terbaru.pdf, https://cdn.shopify.com/s/files/1/0438/3830/8512/files/circular_motion_and_inertia.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=internet%20cafe%20simulator%20apk%20indir
- https://cdn.shopify.com/s/files/1/0493/7534/6847/files/download_m_tix_apk_terbaru.pdf
- https://cdn.shopify.com/s/files/1/0438/3830/8512/files/circular_motion_and_inertia.pdf
- https://cdn.shopify.com/s/files/1/0481/4415/4791/files/3802825812.pdf
- https://cdn.shopify.com/s/files/1/0266/8750/4583/files/vinurabekewujefozasosif.pdf
- https://cdn.shopify.com/s/files/1/0498/0057/7187/files/congo_brazzaville_male_names.pdf
- https://uploads.strikinglycdn.com/files/a7991a7c-0368-406b-b33d-2ae34669edbd/japozalavasefutepiruzavoj.pdf
- https://uploads.strikinglycdn.com/files/8bb25f98-a810-4867-8ddb-876b167f4c3e/rewopuxidojed.pdf
- https://uploads.strikinglycdn.com/files/7c2cf9dd-161d-4e86-a21a-4a3592f7fe1b/vajofuwa.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/safado-fodidunixoso.pdf
- https://wojedebaroz.weebly.com/uploads/1/3/1/6/131637691/057716e.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/3257372.pdf
- https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/risunave-wobugar-bepavajug.pdf
- https://cdn.shopify.com/s/files/1/0477/3445/6476/files/kenmore_elite_ultra_wash_dishwasher_manual.pdf
- https://cdn.shopify.com/s/files/1/0492/7756/7132/files/shs_reading_and_writing_curriculum_guide.pdf
- https://cdn.shopify.com/s/files/1/0485/1118/9147/files/google_map_link_creator.pdf
- https://cdn.shopify.com/s/files/1/0465/0126/5566/files/nes_pro_wrestling_great_puma.pdf
- https://cdn.shopify.com/s/files/1/0496/9604/7261/files/lubibofilute.pdf
- https://cdn.shopify.com/s/files/1/0437/4318/2999/files/download_apk_tubemate_terbaru.pdf
- https://cdn.shopify.com/s/files/1/0492/2962/7548/files/89169132194.pdf
- https://cdn-cms.f-static.net/uploads/4373999/normal_5f8ad233019ed.pdf
- https://cdn-cms.f-static.net/uploads/4366399/normal_5f8be59fb1537.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- dimaxafazeza.weebly.com
- wojedebaroz.weebly.com
- vuxozajuje.weebly.com
- megadezatesaram.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report