SUSPICIOUS — fopumudefixaka.pdf
SUSPICIOUS — fopumudefixaka.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8c2168edb5f643f7f759452ac54896851d46a6c772a647beecb3b1eaf8dcbf3b - SHA-1:
75018e3c5cdc038c5c517137e75362e38d77c270 - MD5:
25281573570e253bf09cfc726e56562b - ssdeep:
768:ygGzpDupSVSnqr9JcCN8cAsJGhkDgLdPf8jL3kEVjxtFtM8kgmzVzj3/L1DbM:vGFqpTCN8cGIgLdPcHpxtFvkJzbBDbM - TLSH:
T15A338EF340A7DE4C7A8BAB879EE71159944AE78C717297A00488276CC4BC6FD7F00952 - Submitted as: fopumudefixaka.pdf
- File type: pdf · Size: 50564 bytes
- Verdict: suspicious (58/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/c7a57fd7-5b03-4f27-b8a6-8028a3ebae89/gopexagasela.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=el%20viaje%20de%20su%20vida, https://cdn.shopify.com/s/files/1/0478/4947/2159/files/nekadas.pdf, https://cdn.shopify.com/s/files/1/0432/7938/4736/files/randys_auto_repair_clearwater_fl.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=el%20viaje%20de%20su%20vida
- https://cdn.shopify.com/s/files/1/0478/4947/2159/files/nekadas.pdf
- https://cdn.shopify.com/s/files/1/0432/7938/4736/files/randys_auto_repair_clearwater_fl.pdf
- https://cdn.shopify.com/s/files/1/0496/2281/0777/files/purple_tablet_subnautica.pdf
- https://cdn.shopify.com/s/files/1/0496/0685/2759/files/observer_dependent_block_craft_pick_up_lines.pdf
- https://cdn.shopify.com/s/files/1/0434/9178/6918/files/which_is_the_largest_and_thickest_layer_of_the_earth.pdf
- https://uploads.strikinglycdn.com/files/c7a57fd7-5b03-4f27-b8a6-8028a3ebae89/gopexagasela.pdf
- https://uploads.strikinglycdn.com/files/be17f028-348c-4228-9f87-0ca5e2afa833/93884435061.pdf
- https://uploads.strikinglycdn.com/files/858d4360-9568-4f94-b4c6-1708a57fc69f/40505310987.pdf
- https://uploads.strikinglycdn.com/files/8e301ba0-88ec-4721-8caf-9e6570c91f51/towiluxovovezivamexobeg.pdf
- https://site-1036698.mozfiles.com/files/1036698/kufuz.pdf
- https://site-1048476.mozfiles.com/files/1048476/marixifikosovepinugifaw.pdf
- https://site-1042548.mozfiles.com/files/1042548/phonics_and_sounds_worksheets.pdf
- https://site-1038835.mozfiles.com/files/1038835/pefejujufelixuw.pdf
- https://site-1042821.mozfiles.com/files/1042821/33737679968.pdf
- https://site-1038510.mozfiles.com/files/1038510/rivat.pdf
- https://uploads.strikinglycdn.com/files/48b9823b-2db9-483b-b301-34bb1100104a/wuworakajerejagoxelafi.pdf
- https://uploads.strikinglycdn.com/files/558d4cd6-c02d-455a-a5e3-31823f046e91/83087132587.pdf
- https://uploads.strikinglycdn.com/files/11454143-32bf-4120-908f-31ba56888aac/radazago.pdf
- https://uploads.strikinglycdn.com/files/cd56e911-fd99-4f25-947a-be9c495b2943/67007724866.pdf
- https://uploads.strikinglycdn.com/files/c6d142dd-4f21-4467-bf24-b54c50c27c8a/xamut.pdf
- https://cdn.shopify.com/s/files/1/0427/7056/3239/files/53948156881.pdf
- https://cdn.shopify.com/s/files/1/0434/3886/6584/files/book_two_we_the_people_of_the_united_states.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1036698.mozfiles.com
- site-1048476.mozfiles.com
- site-1042548.mozfiles.com
- site-1038835.mozfiles.com
- site-1042821.mozfiles.com
- site-1038510.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report