SUSPICIOUS — kusopixezifosufigugu.pdf
SUSPICIOUS — kusopixezifosufigugu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5abd336e5a01311186f037f08382ac41eef795a8c29f96c780f55e61903c00c6 - SHA-1:
995a45b908b83ccfb1ccadf818fe3d2315507594 - MD5:
0ce1ed7512ccc7eb49c47edeeeef24ef - ssdeep:
1536:ZGFSl2QRtIsGAZzQgjS9JzuPfQnG5P3ijOQ6ao:sFSl2iGAZ5G91afVaaQc - TLSH:
T1F834BFF320ABDD8C3B9F5B439DAB155C604AC6882137D36048887A2CC5786FE7F11A61 - Submitted as: kusopixezifosufigugu.pdf
- File type: pdf · Size: 54691 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://sarikawev.avlcbdrx.com/uploads/1/3/0/7/130739127/gowolefovabegazofudo.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=viajeros+dimensionales+pagina+oficia, http://files.tobeman.net/uploads/1/3/0/8/130813887/35ff2d7.pdf, http://files.squarecanvasart.com/uploads/1/3/1/4/131406821/metamanefimun.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=viajeros+dimensionales+pagina+oficia
- http://files.tobeman.net/uploads/1/3/0/8/130813887/35ff2d7.pdf
- http://files.squarecanvasart.com/uploads/1/3/1/4/131406821/metamanefimun.pdf
- http://sarikawev.avlcbdrx.com/uploads/1/3/0/7/130739127/gowolefovabegazofudo.pdf
- http://romukona.sanconsciousco.com/uploads/1/3/1/0/131069806/4183272.pdf
- http://tases.stjhollandfaith.org/uploads/1/3/2/7/132710780/kusuziva-vasoluvo.pdf
- https://site-1037860.mozfiles.com/files/1037860/99425786833.pdf
- https://site-1037881.mozfiles.com/files/1037881/96539834829.pdf
- http://kipawo.klutchcuisine.com/uploads/1/3/0/7/130775470/lazomegebokujat.pdf
- http://files.janeheyesart.com/uploads/1/3/1/3/131380236/ad062c0ee78c3ac.pdf
- http://farem.lllgbbooks.co.uk/uploads/1/3/0/7/130739124/vegunigazurafiniv.pdf
- http://files.pattyschroeder.com/uploads/1/3/1/4/131454355/xelawonuletise.pdf
- http://files.riversideanimalclinicmi.com/uploads/1/3/1/1/131164439/226215.pdf
- https://cdn.shopify.com/s/files/1/0462/0019/3182/files/gigunupafewe.pdf
- https://cdn.shopify.com/s/files/1/0485/1728/3995/files/988_cat_loader_controls.pdf
- https://cdn.shopify.com/s/files/1/0486/0257/9112/files/graphing_motion_kinematics_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0481/6587/9965/files/wednesday_food_talk_ep_166_eng_sub.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- files.tobeman.net
- files.squarecanvasart.com
- sarikawev.avlcbdrx.com
- romukona.sanconsciousco.com
- tases.stjhollandfaith.org
- site-1037860.mozfiles.com
- site-1037881.mozfiles.com
- kipawo.klutchcuisine.com
- files.janeheyesart.com
- farem.lllgbbooks.co.uk
- files.pattyschroeder.com
- files.riversideanimalclinicmi.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report