SUSPICIOUS — bejasu.pdf
SUSPICIOUS — bejasu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
923d67aeb2d6a843db7fd642e9a9d14b13337d41d9faf41c30e40a728c8fa7ad - SHA-1:
7d32b7abca8cfa177b1e4791ad310621fa4e00d7 - MD5:
a2004703bfe016d74acf51c9c71000e8 - ssdeep:
1536:aGFzmNv62Jrb67k+rk5ywnAn8CWL8ULK9+isjo58:DFz32Jrbsk+r1rnw8ULri69 - TLSH:
T1A636AEF3504BEC8D37CA6B03ACA55454B487D7CC31229BA069DC7B7C88B86AC7E51A50 - Submitted as: bejasu.pdf
- File type: pdf · Size: 66107 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/be85706f-cbba-4147-b972-fe81250969f0/13320919005.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=photographic+meaning+in+arabic, https://xigokerurubupa.weebly.com/uploads/1/3/4/3/134312623/mobir.pdf, https://uploads.strikinglycdn.com/files/be85706f-cbba-4147-b972-fe81250969f0/13320919005.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=photographic+meaning+in+arabic
- https://xigokerurubupa.weebly.com/uploads/1/3/4/3/134312623/mobir.pdf
- https://s3.amazonaws.com/fulosobezur/98983937717.pdf
- https://s3.amazonaws.com/juxatop/1979_honda_cm400t_owners_manual.pdf
- https://uploads.strikinglycdn.com/files/be85706f-cbba-4147-b972-fe81250969f0/13320919005.pdf
- https://uploads.strikinglycdn.com/files/484b734a-4cf2-4913-b04e-41ae348b260c/lupiwogosadopigidolereduz.pdf
- https://uploads.strikinglycdn.com/files/68af9c95-f614-40eb-9c44-64e56645275c/mipugamosemopadusa.pdf
- https://rofetavagamufup.weebly.com/uploads/1/3/4/3/134373504/teveguzapo_jifabotusid_mepavogikes.pdf
- https://uploads.strikinglycdn.com/files/df852fe1-1c06-4ba7-bd21-2f06380f69f1/45829829364.pdf
- https://uploads.strikinglycdn.com/files/1aabab6a-bd90-47ae-abf2-1ba3753c8035/telecaster_build_plans.pdf
- https://uploads.strikinglycdn.com/files/c0de2684-4627-41e9-83ce-06f4db39adc7/gituke.pdf
- https://uploads.strikinglycdn.com/files/8bb9ab16-5cd9-480d-87e1-363fd0598d0c/giresesepimam.pdf
- https://uploads.strikinglycdn.com/files/bff8fdef-d77e-4efb-8363-ece590d95461/faxidogagopibodonutun.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/zakeme.pdf
- https://pevinuwipe.weebly.com/uploads/1/3/0/8/130873962/vefewesipelal-rosurajo-kedefer-samibasejaf.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- xigokerurubupa.weebly.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- rofetavagamufup.weebly.com
- dimaxafazeza.weebly.com
- pevinuwipe.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report