SUSPICIOUS — deniwaxeliburu.pdf
SUSPICIOUS — deniwaxeliburu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (42/100). 1 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
565aa28b16133897a2b6db39297cfbc76caf0da480befd589ee2f3a799b511ed - SHA-1:
85ccebc3d03681a44adf8b804678ac1878173b74 - MD5:
88f9d2ab89a175d66ef98fd12bcf10f6 - ssdeep:
768:m4gGzpDDek1EaDbe1GZPo0sIP243Jl+C3bmIR4qzN7aK0fB7jNWV7e/GWKXiQ0d1:iGFXeMjWqlaVdjqUGWKSQM8mn - TLSH:
T1BC316DF310D7EC4CBB8BAB03A9A7146A655EC7892236E790448C772CC57C6BD7D20960 - Submitted as: deniwaxeliburu.pdf
- File type: pdf · Size: 42647 bytes
- Verdict: suspicious (42/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 42/100 is the fusion of 4 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=sara%20rola%20patli%20kamar%20ka%20mp4%20video%20d, https://uploads.strikinglycdn.com/files/89d36c21-6fb0-4042-afc8-f9dcae766853/44252651571.pdf, https://uploads.strikinglycdn.com/files/ad1c2591-38b2-4a56-bcd2-6165a9e05a56/xoxemevuwudovope.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Contacted 4 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
968 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- ff02::1:3
- 224.0.0.252
- 169.254.255.255
- 10.240.0.1
- ff02::16
- ff02::fb
- 10.240.0.255
- 224.0.0.251
- 239.255.255.250
- ff02::2
- ff02::1
- ff02::1:ff12:3456
- 185.125.190.56
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ggtraff.ru/wb?keyword=sara%20rola%20patli%20kamar%20ka%20mp4%20video%20d
- https://uploads.strikinglycdn.com/files/89d36c21-6fb0-4042-afc8-f9dcae766853/44252651571.pdf
- https://uploads.strikinglycdn.com/files/ad1c2591-38b2-4a56-bcd2-6165a9e05a56/xoxemevuwudovope.pdf
- https://uploads.strikinglycdn.com/files/1c871160-9211-406c-8548-428f8629c02a/mimesanizunu.pdf
- https://uploads.strikinglycdn.com/files/634438a5-7bc9-43d3-bebc-32977b467e5d/kugijexad.pdf
- https://cdn.shopify.com/s/files/1/0439/1187/2667/files/elvis_blue_hawaii_album_value.pdf
- https://cdn.shopify.com/s/files/1/0268/8037/7028/files/jurewopizutosamotis.pdf
- https://cdn.shopify.com/s/files/1/0499/0851/4974/files/outlander_book_4_drums_of_autumn.pdf
- https://cdn.shopify.com/s/files/1/0483/9335/5416/files/30792935062.pdf
- https://cdn.shopify.com/s/files/1/0500/9856/9381/files/ffxiv_sohm_al_guide.pdf
- https://cdn-cms.f-static.net/uploads/4368229/normal_5f882db8b20da.pdf
- https://cdn-cms.f-static.net/uploads/4371553/normal_5f895e6f8024a.pdf
- https://cdn-cms.f-static.net/uploads/4386363/normal_5f8cb13dd394e.pdf
- https://cdn-cms.f-static.net/uploads/4379241/normal_5f8ab4ae90be3.pdf
- https://cdn-cms.f-static.net/uploads/4365646/normal_5f8cb64a65a4b.pdf
- https://uploads.strikinglycdn.com/files/14130c89-04be-49b9-98bb-882903ed19c0/97407207290.pdf
- https://uploads.strikinglycdn.com/files/b045ead5-5a68-4106-b340-8bb00a2de9ae/97852111365.pdf
- https://uploads.strikinglycdn.com/files/3312c469-7de6-463a-8a4e-f5eac55807ae/28861175661.pdf
- https://uploads.strikinglycdn.com/files/6e6029aa-46c2-4196-abf5-066c2cc42496/gunugowufotut.pdf
- https://cdn.shopify.com/s/files/1/0498/2131/9323/files/zigolexakazarineb.pdf
- https://cdn.shopify.com/s/files/1/0496/0495/2216/files/realtek_pcie_gbe_family_controller_speed_slow.pdf
- https://cdn.shopify.com/s/files/1/0498/9773/4333/files/gphc_responsible_pharmacist_notice.pdf
- https://cdn.shopify.com/s/files/1/0435/3107/5743/files/jalalanaviraditibivaw.pdf
- https://cdn.shopify.com/s/files/1/0488/4080/2469/files/tommee_tippee_variflow_teats_instructions.pdf
- https://cdn.shopify.com/s/files/1/0492/3008/6297/files/gufovisekasilobadapananal.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 20.184.175.20
- 48.211.4.16
- 172.172.255.216
- 74.178.76.128
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report