SUSPICIOUS — fiwarip.pdf
SUSPICIOUS — fiwarip.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c2a84f21c77fea9170442e603c67a25e9cba79208965dce187d5b05179e6dec0 - SHA-1:
b35bad09947295893bc0312dda6fab1d2acdc720 - MD5:
30c17d8bd27cbf888914fd9a92ae8319 - ssdeep:
768:3gGzpDHp+PRz3CPQcO/IcR6ZBuY6m3Fjg69zAfzl0taG4tkUs:QGFzpseZcR6ZBym3Fjg69sCtEtkUs - TLSH:
T1E4318DF359C7DC8C7A8EAB07ADAA11545189C3087236A76058DC3B6DD4BC9BDBE00D90 - Submitted as: fiwarip.pdf
- File type: pdf · Size: 42484 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/4f5455fd-cbc5-40b4-832f-2d1ff502881e/kesepupududujosi.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=quantum%20mechanics%20mcintyre%20pdf, https://uploads.strikinglycdn.com/files/4f5455fd-cbc5-40b4-832f-2d1ff502881e/kesepupududujosi.pdf, https://uploads.strikinglycdn.com/files/b00e9076-d4d1-44f4-80af-9da5caf31115/rukeperabibu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=quantum%20mechanics%20mcintyre%20pdf
- https://uploads.strikinglycdn.com/files/4f5455fd-cbc5-40b4-832f-2d1ff502881e/kesepupududujosi.pdf
- https://uploads.strikinglycdn.com/files/b00e9076-d4d1-44f4-80af-9da5caf31115/rukeperabibu.pdf
- https://uploads.strikinglycdn.com/files/01ce80ae-e473-4c54-ac7c-7b4c01f3db1a/25501120972.pdf
- https://uploads.strikinglycdn.com/files/d91d8c37-2bd1-4683-8e1e-bb611b9ccb92/basalapokowuvugeveru.pdf
- https://site-1038948.mozfiles.com/files/1038948/povozuzotuma.pdf
- https://site-1043396.mozfiles.com/files/1043396/80396611712.pdf
- https://site-1040785.mozfiles.com/files/1040785/jujalodezipel.pdf
- https://site-1039156.mozfiles.com/files/1039156/nogavokatasotez.pdf
- https://site-1036995.mozfiles.com/files/1036995/sefidekagixegakeg.pdf
- https://uploads.strikinglycdn.com/files/20a42aaf-7452-43e6-9087-ebb443e59fe6/tozimonap.pdf
- https://uploads.strikinglycdn.com/files/0d23cea3-02a7-490b-8ffe-38d47ad4381a/16418044699.pdf
- https://uploads.strikinglycdn.com/files/572b8f97-f7a7-4779-90e9-10ceee9b2414/gijatok.pdf
- https://uploads.strikinglycdn.com/files/d3f3dedc-823b-4892-b2ba-ccf72f2fd4dc/dadigomuzewebenuseken.pdf
- https://uploads.strikinglycdn.com/files/81e3eb48-d6c3-4895-b650-31e0c2d86d2d/83838449607.pdf
- https://cdn.shopify.com/s/files/1/0482/3076/0600/files/dodavem.pdf
- https://cdn.shopify.com/s/files/1/0495/1307/0758/files/43376050580.pdf
- https://uploads.strikinglycdn.com/files/56ae583b-908e-47d7-bfec-89f36cfbff8a/36903571616.pdf
- https://uploads.strikinglycdn.com/files/4e04fc27-aa9e-4c8d-baa9-5532ed08b4b2/30443676711.pdf
- https://uploads.strikinglycdn.com/files/bfe30c4b-8c83-407f-b8f5-260cd975f101/53261299760.pdf
- https://uploads.strikinglycdn.com/files/b6145069-0761-47ed-8efb-4bcd48a129b1/lutidotisixurabuburu.pdf
- https://uploads.strikinglycdn.com/files/b3d34e1b-0420-4a87-94bb-8b19ecd89969/57811877643.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1038948.mozfiles.com
- site-1043396.mozfiles.com
- site-1040785.mozfiles.com
- site-1039156.mozfiles.com
- site-1036995.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report