SUSPICIOUS — ligireziwunezafenud.pdf
SUSPICIOUS — ligireziwunezafenud.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (51/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3b3c35e8279b3e8ffd2d324570e9ae8db2dac461463c801b81a89c736997e1d2 - SHA-1:
38aae5cc4d559a68dd7976b35e93eff9552e3f26 - MD5:
7ed91fef916c066621aa81c38660c40c - ssdeep:
768:LgGzpDMp0y8H9aR+K32m56E1wmn8e+RWbQeronYOzNkm49+IMf4w:0GFgp1835nYOzNN3IMf4w - TLSH:
T1242F5CF310A7DD8C7A8B9B43ADAA1199604AC38D713797500A8D7B3CC9BC5AD3F10961 - Submitted as: ligireziwunezafenud.pdf
- File type: pdf · Size: 34468 bytes
- Verdict: suspicious (51/100)
Detections (2 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 51/100 is the fusion of 3 weighted signals:
- Embedded link rated suspicious by URL analysis: https://wemibevufiwoseb.weebly.com/uploads/1/3/0/8/130813314/zizelox.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=dame%20de%20beber%20marcos%20barrientos, https://cdn-cms.f-static.net/uploads/4368997/normal_5f88520436dde.pdf, https://cdn-cms.f-static.net/uploads/4369143/normal_5f8882ce3175d.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=dame%20de%20beber%20marcos%20barrientos
- https://cdn-cms.f-static.net/uploads/4368997/normal_5f88520436dde.pdf
- https://cdn-cms.f-static.net/uploads/4369143/normal_5f8882ce3175d.pdf
- https://cdn-cms.f-static.net/uploads/4368951/normal_5f87b398e6677.pdf
- https://cdn-cms.f-static.net/uploads/4365542/normal_5f8bf97a5a603.pdf
- https://cdn-cms.f-static.net/uploads/4369654/normal_5f8abfbd09f44.pdf
- https://wemibevufiwoseb.weebly.com/uploads/1/3/0/8/130813314/zizelox.pdf
- https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/5865dafd87775.pdf
- https://goduvozimaku.weebly.com/uploads/1/3/1/3/131380582/298342.pdf
- https://dagigokes.weebly.com/uploads/1/3/0/7/130739756/649272.pdf
- https://cdn-cms.f-static.net/uploads/4376088/normal_5f8a595d5d39b.pdf
- https://cdn-cms.f-static.net/uploads/4366676/normal_5f87d91e50e99.pdf
- https://nalabusapigo.weebly.com/uploads/1/3/2/7/132740218/1850716.pdf
- https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/8843389.pdf
- https://vikumeniwexawud.weebly.com/uploads/1/3/0/9/130969440/ac9149829f3.pdf
- https://medizagokitoni.weebly.com/uploads/1/3/2/3/132303310/davevifuviwizo_vopurudige_jalekuxagud_daxamafira.pdf
- https://cdn.shopify.com/s/files/1/0504/2064/6048/files/hipaa_guidelines_for_social_media.pdf
- https://cdn.shopify.com/s/files/1/0478/9773/9430/files/thnh_ph_hoa_lin_i_loan.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- wemibevufiwoseb.weebly.com
- kabudededawizo.weebly.com
- goduvozimaku.weebly.com
- dagigokes.weebly.com
- nalabusapigo.weebly.com
- fodezamu.weebly.com
- vikumeniwexawud.weebly.com
- medizagokitoni.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report