SUSPICIOUS — kuwurosa-nefotadibalomu.pdf
SUSPICIOUS — kuwurosa-nefotadibalomu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
667efcea4d5633042415e1dfddb646381f8c05aa3348bf9bc69217b4187e9e1d - SHA-1:
b9e161a12c1aceeaa53629260d94f6747a44d357 - MD5:
f6e502b15f473da64bae43c16c4d0304 - ssdeep:
1536:eGFTp+HKK7/wWdKKj06BSKvNsV4iI43eQ+j:HFTpMN7/jcKKV4iz3e7 - TLSH:
T19A34A0F300A7EC8C7A875B83BCAB16A96185D7C86136E3540488762CD5BC6FD7F11892 - Submitted as: kuwurosa-nefotadibalomu.pdf
- File type: pdf · Size: 54197 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/a691d603-2803-4aed-980f-bbaf886d8fe6/6833483070.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=ben%20can%20tam%20be%C5%9F%20ya%C5%9F%C4%B1nday%C4%B1m%20m%C3%BCzi%C4%9Fi, https://cdn.shopify.com/s/files/1/0430/5515/3303/files/irrigation_methods_fao.pdf, https://cdn.shopify.com/s/files/1/0503/1411/7293/files/file_splitter_and_joiner_apk_free_download.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=ben%20can%20tam%20be%C5%9F%20ya%C5%9F%C4%B1nday%C4%B1m%20m%C3%BCzi%C4%9Fi
- https://cdn.shopify.com/s/files/1/0430/5515/3303/files/irrigation_methods_fao.pdf
- https://cdn.shopify.com/s/files/1/0503/1411/7293/files/file_splitter_and_joiner_apk_free_download.pdf
- https://cdn.shopify.com/s/files/1/0440/1653/3654/files/xtreme_good_guys_vs_bad_guys_best_crazy_games.pdf
- https://cdn.shopify.com/s/files/1/0486/5805/5318/files/subway_surfers_unlock_all_characters_apk_download.pdf
- https://uploads.strikinglycdn.com/files/a691d603-2803-4aed-980f-bbaf886d8fe6/6833483070.pdf
- https://uploads.strikinglycdn.com/files/7c14e1d9-dbb9-4b52-947a-ae558c602b83/54945893822.pdf
- https://uploads.strikinglycdn.com/files/b65e5b96-ae8c-4eac-b3f6-b160b493ddc1/74601921860.pdf
- https://uploads.strikinglycdn.com/files/e745e718-bfa3-4ca8-b0cd-e5be74a384a3/daduvelajo.pdf
- https://uploads.strikinglycdn.com/files/05a9efaf-53e9-4bd8-a1f2-ca3585bdc24b/91835337939.pdf
- https://cdn.shopify.com/s/files/1/0500/6976/6302/files/noukadubi_novel_in_english.pdf
- https://cdn.shopify.com/s/files/1/0494/1152/2727/files/wubaj.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/xopevu_vilugarokobijos_fimorekon.pdf
- https://xonimitofowe.weebly.com/uploads/1/3/2/6/132682232/188322e805b2b63.pdf
- https://xovadodelemowuz.weebly.com/uploads/1/3/1/3/131383330/5713311.pdf
- https://godadonalizubo.weebly.com/uploads/1/3/1/4/131437317/1706706.pdf
- https://ridolagu.weebly.com/uploads/1/3/0/7/130775195/zixekew.pdf
- https://uploads.strikinglycdn.com/files/3cefc30b-5445-4ad1-bf0f-2d2ac18624cd/difolevu.pdf
- https://uploads.strikinglycdn.com/files/a9575d50-21cb-45b0-b56c-1ac67dc13624/rivazubudasefobemasisik.pdf
- https://uploads.strikinglycdn.com/files/f759aca2-57eb-433c-97f5-a460b6fc4591/tonanufegavaligij.pdf
- https://cdn-cms.f-static.net/uploads/4368767/normal_5f87f4399ad8b.pdf
- https://cdn-cms.f-static.net/uploads/4368971/normal_5f87ee8dd7806.pdf
- https://cdn-cms.f-static.net/uploads/4378857/normal_5f8a75f93b116.pdf
- https://cdn-cms.f-static.net/uploads/4367914/normal_5f87a856acdb0.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- jawasolasazilem.weebly.com
- xonimitofowe.weebly.com
- xovadodelemowuz.weebly.com
- godadonalizubo.weebly.com
- ridolagu.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report