SUSPICIOUS — bixofomumokikatalakuxewa.pdf
SUSPICIOUS — bixofomumokikatalakuxewa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4ad65b474aa6461fe0fd1368c111210483603834ac10d603649c9e8ae38be3e3 - SHA-1:
7ee2373a99c365665e6f4760fe189220080ccffc - MD5:
5f40d3e620e6a4e15a17ec4b98740163 - ssdeep:
768:AgGzpDkgwd56WtsreVW1Ye+AdZrwSEWA/Ok4Uq5Ki0:NGFwIeVW1vdrwSEfOk4p5Ki0 - TLSH:
T11431AFF39097ED8C7687AB03ADFB116A6085C34C6136A6B044C87B6DC4BC2BD7E51821 - Submitted as: bixofomumokikatalakuxewa.pdf
- File type: pdf · Size: 41889 bytes
- Verdict: suspicious (58/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/6310cd98-d674-43dc-8486-582ad0ef4f71/bejigesutesakavanuwe.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=urban+sociology+pdf, https://site-1037193.mozfiles.com/files/1037193/66310497206.pdf, https://site-1040424.mozfiles.com/files/1040424/23208366466.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=urban+sociology+pdf
- https://site-1037193.mozfiles.com/files/1037193/66310497206.pdf
- https://site-1040424.mozfiles.com/files/1040424/23208366466.pdf
- https://site-1039814.mozfiles.com/files/1039814/83520079555.pdf
- https://site-1039183.mozfiles.com/files/1039183/96948278579.pdf
- https://uploads.strikinglycdn.com/files/6310cd98-d674-43dc-8486-582ad0ef4f71/bejigesutesakavanuwe.pdf
- https://uploads.strikinglycdn.com/files/2655c19d-7e9c-49d5-a5dd-6008519fc9cb/20185981242.pdf
- https://uploads.strikinglycdn.com/files/b280f555-9bf0-4539-9a10-d3df310a18d0/78338368477.pdf
- https://uploads.strikinglycdn.com/files/a9503106-6537-4784-8cb9-35af85c00a1e/bowakixefidurabexebaro.pdf
- https://uploads.strikinglycdn.com/files/e2bb1fde-fb39-4a38-907d-c072495379ce/18653377585.pdf
- http://patilok.4141coffeehouse.com/uploads/1/3/0/7/130775404/7704378.pdf
- http://files.chestnutcenter.org/uploads/1/3/1/6/131636843/belera.pdf
- http://gidogu.erikahanneson.com/uploads/1/3/0/8/130874493/fokidapokifilam-biver-giripufawaxe.pdf
- http://files.chisholmtrailexpo.com/uploads/1/3/1/4/131437393/bumugo-zuzujapasufesiz.pdf
- http://surol.emmyandjesse.com/uploads/1/3/0/9/130969757/jiwew.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1037193.mozfiles.com
- site-1040424.mozfiles.com
- site-1039814.mozfiles.com
- site-1039183.mozfiles.com
- uploads.strikinglycdn.com
- patilok.4141coffeehouse.com
- files.chestnutcenter.org
- gidogu.erikahanneson.com
- files.chisholmtrailexpo.com
- surol.emmyandjesse.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report