SUSPICIOUS — xolutelokorato_bovirikag_mafisuzorane_fuxakijob.pdf
SUSPICIOUS — xolutelokorato_bovirikag_mafisuzorane_fuxakijob.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
cd2fcf9db92c99b184a57f4de3e7a9ab66900af35ef823fbd65923ca71d9bb43 - SHA-1:
1d77babfd8b61029a54c1250d770e5e53b158f40 - MD5:
ab9eeacc5cca1cd192b22e858a9b6934 - ssdeep:
1536:PRNbC5I56Ps88hV858YaTVlAuQnuNmeda4xPC/AXswyjWLxklL23vVcTckGIrjzN:ptWA60HDE+V2Hnf/7wWlL2f0ZGA1 - TLSH:
T1A837DFB36263DC8CE6821B432AFA552C158AD7887436B76040CC7E7CC9785BE7E54DA0 - Submitted as: xolutelokorato_bovirikag_mafisuzorane_fuxakijob.pdf
- File type: pdf · Size: 72129 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://static1.squarespace.com/static/5fc6b1d9403f5353fdbe0a77/t/5fd6dfe2de5b1220c03da1c9/1607917539251/dovobutaviputebo.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://trafffe.ru/wb?keyword=offline%20bike%20racing%20games%20apk, https://uploads.strikinglycdn.com/files/41f7f5e2-c94a-4165-88ec-09345412100b/26067248605.pdf, https://cdn-cms.f-static.net/uploads/4377125/normal_5f9f93f9044ea.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffe.ru/wb?keyword=offline%20bike%20racing%20games%20apk
- https://uploads.strikinglycdn.com/files/41f7f5e2-c94a-4165-88ec-09345412100b/26067248605.pdf
- https://cdn-cms.f-static.net/uploads/4377125/normal_5f9f93f9044ea.pdf
- https://static1.squarespace.com/static/5fc6b1d9403f5353fdbe0a77/t/5fd6dfe2de5b1220c03da1c9/1607917539251/dovobutaviputebo.pdf
- https://static1.squarespace.com/static/5fc0f66f116eb00e3c4c456d/t/5fc4013ce18c5c478e77e5e2/1606680892705/schwinn_830_treadmill_manual.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf5ff9cb3e0f57714713a2/1606377465619/dezinefesujowolidanusaxo.pdf
- https://static1.squarespace.com/static/5fcf16c5affad1251da7f72e/t/5fd19d768185f4776a094275/1607572854500/free_forbes_magazine_subscription_2018.pdf
- https://static1.squarespace.com/static/5fc0d766a3bf4b14aba8e616/t/5fc0f46efa04221c7141f0d2/1606481008410/enterasys_switch_command_guide.pdf
- https://uploads.strikinglycdn.com/files/2fd71bb4-2b87-4d23-ad09-a6bb23c5b782/how_to_spawn_arceus_in_pixelmon.pdf
- https://uploads.strikinglycdn.com/files/5c93c5a9-69f8-4807-b5ff-afc23333176e/drops_in_the_bucket_answer_key_level_a.pdf
- https://cdn-cms.f-static.net/uploads/4495040/normal_5fbc872ac29cd.pdf
- https://uploads.strikinglycdn.com/files/21d40043-4375-4718-b7d2-341728ac017f/common_and_proper_nouns_worksheet_answer_key.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffe.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- static1.squarespace.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report