SUSPICIOUS — kubabifupapiliruri.pdf
SUSPICIOUS — kubabifupapiliruri.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b4a459185388324937523a90fa870bb0e7f3e0e1caf11cd741ad8535c6a93f2b - SHA-1:
8d7ec757c931583d881459485b0526269cb4fdf4 - MD5:
ac9cf2e87731b5e26d319949ad13ae38 - ssdeep:
768:YgGzpDCxFCZGVghMIoNNhez+YQWN3PHerTceA/HPIVD2fMHTRQIS4DtoQErIp7Av:1GFuaZxy1NpYLZPUaPPEH1JnxDf7Av - TLSH:
T11433AEF311ABED4C668A9B03ADE721688985C7CCA133D760059C7B6DC4BC6BD3E11990 - Submitted as: kubabifupapiliruri.pdf
- File type: pdf · Size: 49501 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://jesasifewom.weebly.com/uploads/1/3/1/4/131453969/weledusew-finalaneze-vapekiposi.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=electrostatic%20potential%20and%20capacitance%20class%2012%20pdf, https://jikeberu.weebly.com/uploads/1/3/1/8/131857846/2c14cc6b.pdf, https://pojutawetuje.weebly.com/uploads/1/3/1/3/131382470/d16abb89ab01ba3.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=electrostatic%20potential%20and%20capacitance%20class%2012%20pdf
- https://jikeberu.weebly.com/uploads/1/3/1/8/131857846/2c14cc6b.pdf
- https://pojutawetuje.weebly.com/uploads/1/3/1/3/131382470/d16abb89ab01ba3.pdf
- https://zalopajozi.weebly.com/uploads/1/3/1/4/131453352/tikuritodebekes.pdf
- https://jesasifewom.weebly.com/uploads/1/3/1/4/131453969/weledusew-finalaneze-vapekiposi.pdf
- https://uploads.strikinglycdn.com/files/db1ee10a-e79c-4551-9f4b-115db626f1ef/54238499575.pdf
- https://uploads.strikinglycdn.com/files/78fd5a01-caa4-4319-aaf0-f065a6afeabe/83161796615.pdf
- https://uploads.strikinglycdn.com/files/0cb828b9-ca10-48cb-99cb-4d8e159ab869/tonoji.pdf
- https://cdn.shopify.com/s/files/1/0429/4528/2214/files/gluten_free_dumpling_wrappers.pdf
- https://cdn.shopify.com/s/files/1/0492/8566/0828/files/master_editor_crack_mac.pdf
- https://cdn.shopify.com/s/files/1/0481/5867/1015/files/zalamumobewixeko.pdf
- https://uploads.strikinglycdn.com/files/b1743d77-1902-4fd1-a285-4cf1741d4ec4/xamanawuneninujaxojudata.pdf
- https://uploads.strikinglycdn.com/files/af9308ef-c294-4bd2-9f40-6754b901b133/sukubomuno.pdf
- https://uploads.strikinglycdn.com/files/e0479a28-08ea-4c3a-8255-e5dd733ebcd4/75584923748.pdf
- https://uploads.strikinglycdn.com/files/c5b4a755-e512-4e8e-9be4-bad9d764cd71/osrs_blast_mining_guide.pdf
- https://uploads.strikinglycdn.com/files/5161d642-7ae6-43e2-8b05-5f967e3afdb2/honeywell_3000_thermostat_manual.pdf
- https://s3.amazonaws.com/petikamov/hazardous_materials_training.pdf
- https://s3.amazonaws.com/jojitagifuva/49131862856.pdf
- https://lokixesope.weebly.com/uploads/1/3/1/6/131607163/zuzokarasig.pdf
- https://foduxami.weebly.com/uploads/1/3/4/4/134452333/defasenalor.pdf
- https://dejolezeg.weebly.com/uploads/1/3/2/8/132815968/siluvilasoniz.pdf
- https://kurikezexiwu.weebly.com/uploads/1/3/0/7/130775092/4979109.pdf
- https://zelapagetuwuj.weebly.com/uploads/1/3/1/4/131406140/muruwuximusovid.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- jikeberu.weebly.com
- pojutawetuje.weebly.com
- zalopajozi.weebly.com
- jesasifewom.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- s3.amazonaws.com
- lokixesope.weebly.com
- foduxami.weebly.com
- dejolezeg.weebly.com
- kurikezexiwu.weebly.com
- zelapagetuwuj.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- s:\O7
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report