SUSPICIOUS — xafapivukowezinul.pdf
SUSPICIOUS — xafapivukowezinul.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
465b6ab0a925bf1b00c2640dec7391556260b917ba036a617c6ea041a7a0bdde - SHA-1:
89049d9fb09d4c4daca4c7358bb3c516cd155a4b - MD5:
0da6070a424bbf508c109e6821fd4457 - ssdeep:
768:igGzpDQp4HthUJJWileE0y80MuXfMkU6UVhoolhGS7XHq10vnGwwKjfRb:/GFcpOspfg649YS73q10vnXfRb - TLSH:
T14F337CF311E3DF8C7A8B5B4B6EE6199A544AD34862379BD0308C376CC5786AD2F14860 - Submitted as: xafapivukowezinul.pdf
- File type: pdf · Size: 48471 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/47a7bde3-03c8-4f84-a40d-88b13736986b/68935621355.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=retorica%20de%20la%20imagen%20roland%20barthes, https://mogezisatizate.weebly.com/uploads/1/3/0/7/130775403/zejusedezegem.pdf, https://folarudivol.weebly.com/uploads/1/3/1/8/131871739/kijode-guwetoka-lowasufa-gejuxu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=retorica%20de%20la%20imagen%20roland%20barthes
- https://mogezisatizate.weebly.com/uploads/1/3/0/7/130775403/zejusedezegem.pdf
- https://folarudivol.weebly.com/uploads/1/3/1/8/131871739/kijode-guwetoka-lowasufa-gejuxu.pdf
- https://sokuvotaboraj.weebly.com/uploads/1/3/0/7/130776263/nudikajarino_gobamisiwolu_doturadofikefu.pdf
- https://fotejisatowonu.weebly.com/uploads/1/3/2/3/132302873/1370743.pdf
- https://uploads.strikinglycdn.com/files/47a7bde3-03c8-4f84-a40d-88b13736986b/68935621355.pdf
- https://uploads.strikinglycdn.com/files/d3fdd874-be43-4f5a-928d-9fafbeac9856/radapunafafopa.pdf
- https://uploads.strikinglycdn.com/files/1a2d46e6-075b-4a6c-9e91-d3afbcccec38/96663628525.pdf
- https://uploads.strikinglycdn.com/files/4eb3811f-6b10-4eee-a7f8-7685a5dc1ce6/4runner_blind_spot_monitor.pdf
- https://uploads.strikinglycdn.com/files/c80a41e0-5078-4f7b-b3d9-579a75dbaad6/lakopa.pdf
- https://uploads.strikinglycdn.com/files/fca1ae50-a02c-4237-af98-d441187b23aa/rapipagos_quateur_rel_sois.pdf
- https://uploads.strikinglycdn.com/files/23640b17-235a-4e46-bd81-76e87cdf425f/amd_graphics_driver_not_working.pdf
- https://uploads.strikinglycdn.com/files/ddfe8229-3b13-44d8-b7ab-7a476f90533d/98879696673.pdf
- https://uploads.strikinglycdn.com/files/578707af-e80d-4a66-bd1d-6de43eb1a4b7/30015781041.pdf
- https://cdn-cms.f-static.net/uploads/4380411/normal_5f8cf0c3463eb.pdf
- https://cdn-cms.f-static.net/uploads/4367004/normal_5f872a27dab0b.pdf
- https://cdn-cms.f-static.net/uploads/4368235/normal_5f8783bf9aca0.pdf
- https://cdn-cms.f-static.net/uploads/4366354/normal_5f8755a608f06.pdf
- https://cdn-cms.f-static.net/uploads/4376879/normal_5f8cbaa9070d6.pdf
- https://cdn-cms.f-static.net/uploads/4366000/normal_5f87045cc7312.pdf
- https://cdn-cms.f-static.net/uploads/4366325/normal_5f87271762e3c.pdf
- https://cdn-cms.f-static.net/uploads/4366007/normal_5f87053d62b3e.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f8789a0a47ec.pdf
- https://cdn-cms.f-static.net/uploads/4377407/normal_5f8a72cdb5e2f.pdf
- https://cdn.shopify.com/s/files/1/0433/8712/5910/files/shadar_kai_elf_names.pdf
Embedded domains
- gettraff.ru
- mogezisatizate.weebly.com
- folarudivol.weebly.com
- sokuvotaboraj.weebly.com
- fotejisatowonu.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 3.0.7.9
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report