SUSPICIOUS — pirazudezovadut.pdf
SUSPICIOUS — pirazudezovadut.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
658e60e3e6eedbd4ba5380f6bb1622260cec338c756bbf8c1d00d4dbc35a9f07 - SHA-1:
5f73a21221e73f45381cbf64e29f1f6a01eafd90 - MD5:
3c1908d41d0248f018ae999e06448ef6 - ssdeep:
1536:KbLj1j2JzN++OocTHWhXWo+Dh+sTCkVgabJuB:21jq/5c7sgh+WC8guu - TLSH:
T1D036DFF3B09BCCCCBD864F1369BA5A997199C78E1132C2E904D57A2CC1781EDBE21911 - Submitted as: pirazudezovadut.pdf
- File type: pdf · Size: 67349 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://static1.squarespace.com/static/5fc5ce28e9fc3622d5438a9f/t/5fc671669d793648406b07a4/1606840679391/tumblr_girl_dog_names.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://trafffe.ru/wb?keyword=sql%20formatter%20ssms%20plugin, https://metufudosajaf.weebly.com/uploads/1/3/4/0/134012305/denelodevofurav.pdf, https://uploads.strikinglycdn.com/files/c6349376-a093-4589-aa69-7b86879ed35a/what_cell_provides_temporary_storage_of_food_enzymes_and_waste_products.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffe.ru/wb?keyword=sql%20formatter%20ssms%20plugin
- https://s3.amazonaws.com/lodazojamuva/bishop_guide_maplelegends.pdf
- https://metufudosajaf.weebly.com/uploads/1/3/4/0/134012305/denelodevofurav.pdf
- https://uploads.strikinglycdn.com/files/c6349376-a093-4589-aa69-7b86879ed35a/what_cell_provides_temporary_storage_of_food_enzymes_and_waste_products.pdf
- https://static1.squarespace.com/static/5fc5ce28e9fc3622d5438a9f/t/5fc671669d793648406b07a4/1606840679391/tumblr_girl_dog_names.pdf
- https://uploads.strikinglycdn.com/files/005fba92-178f-424a-a656-7bd6827a9bf8/53112942948.pdf
- https://uploads.strikinglycdn.com/files/0ecdafcb-8177-491b-8416-d546f2244d28/verusigobigi.pdf
- https://s3.amazonaws.com/mijedusovineti/14717422764.pdf
- https://s3.amazonaws.com/tikofaketonub/critical_role_2nd_campaign_character_sheets.pdf
- https://s3.amazonaws.com/pugomonapoxuxe/betaflight_3._5._0.pdf
- https://uploads.strikinglycdn.com/files/b2e576d6-1418-43e8-b093-c167d2ad59f3/77432203952.pdf
- https://uploads.strikinglycdn.com/files/719598f3-0617-448e-a675-e25d4ab69112/tunifusijox.pdf
- https://dozisinabi.weebly.com/uploads/1/3/4/6/134646642/e5db81534.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffe.ru
- s3.amazonaws.com
- metufudosajaf.weebly.com
- uploads.strikinglycdn.com
- static1.squarespace.com
- dozisinabi.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report