SUSPICIOUS — zunajabufabi.pdf
SUSPICIOUS — zunajabufabi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a0286cbd2ab0f1b79f350dc7a8267cc1fdacc8e1e00bddc57aa8f5f042f1ab68 - SHA-1:
966b3f71d98e730652934bc7de2e63b5c50c5b30 - MD5:
58447d86efeeab6181bae432e9b7314e - ssdeep:
768:igGzpDCp3g1GfnNEnIGWsU2TbvVILw5aZow5lC8WCO8KRaD1/X:/GF2pbNlTHUv65o4lC8WCcR0X - TLSH:
T114329DF31193ED8CBA8B9B0799BB109A648AD74D2137D3A444C8BB7CC07C4ADBE50911 - Submitted as: zunajabufabi.pdf
- File type: pdf · Size: 44727 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://jimigafekalese.weebly.com/uploads/1/3/1/4/131407537/1298047.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=factors%20determining%20price%20elasticity%20of%20demand%20pdf, https://cdn-cms.f-static.net/uploads/4387565/normal_5f95d9be66853.pdf, https://cdn-cms.f-static.net/uploads/4366369/normal_5f8c39e6c47fd.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=factors%20determining%20price%20elasticity%20of%20demand%20pdf
- https://cdn-cms.f-static.net/uploads/4387565/normal_5f95d9be66853.pdf
- https://cdn-cms.f-static.net/uploads/4366369/normal_5f8c39e6c47fd.pdf
- https://cdn-cms.f-static.net/uploads/4408588/normal_5f97554b6c106.pdf
- https://jimigafekalese.weebly.com/uploads/1/3/1/4/131407537/1298047.pdf
- https://jarapitoxedomel.weebly.com/uploads/1/3/1/4/131437170/94b984da07c.pdf
- https://uploads.strikinglycdn.com/files/e90282c4-daad-43ed-99d9-d4e2447825aa/39891234164.pdf
- https://uploads.strikinglycdn.com/files/eda9effa-a89b-43a2-809a-54e701deadc3/losuvejutisu.pdf
- https://uploads.strikinglycdn.com/files/8f42a095-3fae-47ae-8f9e-d589f958ded1/nexox.pdf
- https://uploads.strikinglycdn.com/files/0011d82b-b78c-4e7a-b2e0-db918b6ed3c6/weviselufezi.pdf
- https://uploads.strikinglycdn.com/files/e3f4ee15-d040-4fbd-a1f4-ce3fd601f20d/44229026259.pdf
- https://uploads.strikinglycdn.com/files/995076e3-a4ff-4bde-851b-dcb7e270f279/fitajofar.pdf
- https://uploads.strikinglycdn.com/files/07c56d7f-4912-43e7-b39a-85778ff210a7/46818537587.pdf
- https://uploads.strikinglycdn.com/files/44a8c265-3c0d-4133-889b-3d2a73072c73/a_businesss_set_of_financial_statements_includes_which_of_the_following_items.pdf
- https://uploads.strikinglycdn.com/files/4cf381c4-8120-4de7-a9fb-c002e7673fb4/nawemixikirokubik.pdf
- https://uploads.strikinglycdn.com/files/8414927c-f5d7-4b5f-8b7b-8473f8e224ed/tebamuzed.pdf
- https://uploads.strikinglycdn.com/files/a3de2b0d-034b-40f9-815c-bf98722ae466/xuterodabedurazov.pdf
- https://s3.amazonaws.com/henghuili-files/37267066424.pdf
- https://s3.amazonaws.com/wonoti/sedimoperabu.pdf
- https://s3.amazonaws.com/sugaguxagu/how_to_annotate_in_notability.pdf
- https://s3.amazonaws.com/mibiwivanetuj/regrouper_plusieurs_fichiers_en_un_seul.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- jimigafekalese.weebly.com
- jarapitoxedomel.weebly.com
- uploads.strikinglycdn.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report