SUSPICIOUS — powirul.pdf
SUSPICIOUS — powirul.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
613d8c39a1b127d6a3474bba128fd190453ea946c3a5ae6f3e32e36424d82e3c - SHA-1:
faecfa53dea1018ae3fe54f3da1db01e8ffa143b - MD5:
cfe708421b87e6e9d6480bd39e44d5fe - ssdeep:
768:6gGzpDUpJLZRHKmMuOPx19+zkhEyJFNtiUW2zUwr1aiyeVHJg56FEK7+:nGFgpVM11kzYEeFNtvW2YgMiyejg56WT - TLSH:
T123319EF390D7EC4C7A8B9B436DBA20A95589C748A037C3A0498C773DD4BC6BC6E50961 - Submitted as: powirul.pdf
- File type: pdf · Size: 42554 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/a168a9c1-51e3-4c9a-8bc6-74c215ca26fa/wefavidaxuvoj.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=jodelle%20ferland%20girl%20fight%202011%20tv%20m, https://cdn-cms.f-static.net/uploads/4366316/normal_5f870f02a88c8.pdf, https://cdn-cms.f-static.net/uploads/4366040/normal_5f86f98540800.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=jodelle%20ferland%20girl%20fight%202011%20tv%20m
- https://cdn-cms.f-static.net/uploads/4366316/normal_5f870f02a88c8.pdf
- https://cdn-cms.f-static.net/uploads/4366040/normal_5f86f98540800.pdf
- https://cdn-cms.f-static.net/uploads/4365621/normal_5f8714e0d00a4.pdf
- https://cdn-cms.f-static.net/uploads/4370777/normal_5f889e1584451.pdf
- https://vuxilimibipemop.weebly.com/uploads/1/3/1/4/131453056/midofajewugawapu.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/038885c85ecf8f0.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/wotareropajewub.pdf
- https://uploads.strikinglycdn.com/files/a168a9c1-51e3-4c9a-8bc6-74c215ca26fa/wefavidaxuvoj.pdf
- https://uploads.strikinglycdn.com/files/d9ca71a2-7887-42ae-9486-ffd5419bbfd6/lezuvaje.pdf
- https://uploads.strikinglycdn.com/files/5cccc351-4565-468e-992f-665a4d95a921/pejusedixaraw.pdf
- https://uploads.strikinglycdn.com/files/f6179a3f-2b55-4ae1-b1d7-59d3cdd4f080/barolinebereripurawubobos.pdf
- https://uploads.strikinglycdn.com/files/1c7d96d5-dcf9-473e-bb04-5df3f375c20f/38934586080.pdf
- https://uploads.strikinglycdn.com/files/fa8607ad-e743-4806-b20b-676229b49fdb/112173267.pdf
- https://cdn-cms.f-static.net/uploads/4367646/normal_5f8754b30d5ec.pdf
- https://cdn-cms.f-static.net/uploads/4369323/normal_5f87d407a4b1f.pdf
- https://uploads.strikinglycdn.com/files/3dc4800a-928a-4ff1-9d09-85cef06a2bc1/vomekabegeruwibividit.pdf
- https://uploads.strikinglycdn.com/files/ef86464a-bdc2-4ea1-b861-03de976531ef/96255249186.pdf
- https://uploads.strikinglycdn.com/files/1d9dce11-6bef-441d-9df6-36edf6d52930/bebafuwanixelapexufume.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- vuxilimibipemop.weebly.com
- mojivimimujovo.weebly.com
- gimejexoxixaza.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report