SUSPICIOUS — daganuke-mewodubelufib.pdf
SUSPICIOUS — daganuke-mewodubelufib.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c849f1e88663672730130716fb0f42473bfe3feee4a8cca47817244fca26d7df - SHA-1:
4bad4eec7808af08129a189c3979d3bb680863c4 - MD5:
d92fcfa37aa4e98ea396c0edca05f5ed - ssdeep:
768:jgGzpDBpFoAnE5POo3SSAPfgsbFbklHPfSUYDbZ4vE+gJK:cGFlpFr5klvfSUY0E+gJK - TLSH:
T13D306DF310E7ED8C7EC69F43AAEA245D948AD68C603293644488772DC47C7BD7E50A60 - Submitted as: daganuke-mewodubelufib.pdf
- File type: pdf · Size: 38220 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://vabeliguteziji.weebly.com/uploads/1/3/1/3/131379360/busamoto.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=ets%202%20best%20truck, https://gikoberi.weebly.com/uploads/1/3/0/9/130969260/dd85eafa1ce59.pdf, https://sanuvexugivi.weebly.com/uploads/1/3/1/6/131606490/rumori.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=ets%202%20best%20truck
- https://gikoberi.weebly.com/uploads/1/3/0/9/130969260/dd85eafa1ce59.pdf
- https://sanuvexugivi.weebly.com/uploads/1/3/1/6/131606490/rumori.pdf
- https://vabeliguteziji.weebly.com/uploads/1/3/1/3/131379360/busamoto.pdf
- https://lirebuzufosol.weebly.com/uploads/1/3/1/4/131453665/fejuwekukizuxitux.pdf
- https://uploads.strikinglycdn.com/files/877aacad-8f78-45c7-bffd-c24b983cfce7/vatar.pdf
- https://uploads.strikinglycdn.com/files/5d6ce8df-45a3-495e-bf13-d4382666df70/malegotopazewamajajulu.pdf
- https://uploads.strikinglycdn.com/files/279d105c-cd8d-4acc-88b1-b28da11e9b51/rotovinulozifojova.pdf
- https://uploads.strikinglycdn.com/files/52de9d1e-0f40-4bab-936f-0d1f43b686b4/pozuvaxazetis.pdf
- https://uploads.strikinglycdn.com/files/3bf52b8b-46f5-43b6-8ff7-ef90a069dc31/pevudupulozowaw.pdf
- https://uploads.strikinglycdn.com/files/0fbcaec5-30cd-44c7-b994-dae5fa58942a/4072939117.pdf
- https://uploads.strikinglycdn.com/files/d4f9336a-b31d-46ca-a9b1-e3c0ea1bcf4e/jane_schaffer_paragraph.pdf
- https://cdn-cms.f-static.net/uploads/4372967/normal_5f896822add5d.pdf
- https://cdn-cms.f-static.net/uploads/4374374/normal_5f892a279af69.pdf
- https://cdn.shopify.com/s/files/1/0488/0623/2229/files/10196745859.pdf
- https://cdn.shopify.com/s/files/1/0486/0788/7518/files/39235244076.pdf
- https://cdn.shopify.com/s/files/1/0497/4211/9073/files/basuxezukujelafuw.pdf
- https://cdn.shopify.com/s/files/1/0496/4469/9799/files/85056223862.pdf
- https://cdn.shopify.com/s/files/1/0431/7118/4794/files/20796531437.pdf
- https://gukaguse.weebly.com/uploads/1/3/1/3/131398473/felidenujaga-zuvamekibo-somiduzaronog.pdf
- https://kixatefibav.weebly.com/uploads/1/3/0/7/130776592/999b88af52b1014.pdf
- https://fimozafovobas.weebly.com/uploads/1/3/2/7/132741130/ninukisof.pdf
- https://tevirilozarenov.weebly.com/uploads/1/3/2/6/132695732/kisanajorave-godoruwuz-fakuwur.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- gikoberi.weebly.com
- sanuvexugivi.weebly.com
- vabeliguteziji.weebly.com
- lirebuzufosol.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- gukaguse.weebly.com
- kixatefibav.weebly.com
- fimozafovobas.weebly.com
- tevirilozarenov.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report