SUSPICIOUS — bitidovalobusefimuse.pdf
SUSPICIOUS — bitidovalobusefimuse.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d484b609e055614464fe9d3eab6cd990cb0aea3241cc1d379a06a324df269cf3 - SHA-1:
c37e6985b5280957376b3c571f562bcd5c5c8a13 - MD5:
4853c7d9b7bbe7a727d7397fc5573d95 - ssdeep:
768:xgGzpDMpT5MNhBnI+u27e6aso2ljRFuOkWbu+KrpgT+GvuSwtyzk:CGFQps7p3ljwd+KrpgTBuSwtyzk - TLSH:
T13C338DF350D3ED8C7A87AB036DEB255AA049E28C20739B64409C772DD57C6BE7E10A10 - Submitted as: bitidovalobusefimuse.pdf
- File type: pdf · Size: 50518 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/eb2a79a8-f087-4333-835f-646b309c6778/67781993915.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=dark%20set%20ds2, https://uploads.strikinglycdn.com/files/eb2a79a8-f087-4333-835f-646b309c6778/67781993915.pdf, https://uploads.strikinglycdn.com/files/0c2d8d50-68c1-4102-a928-e3d39c68199f/zikifakupelulosabaro.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=dark%20set%20ds2
- https://uploads.strikinglycdn.com/files/eb2a79a8-f087-4333-835f-646b309c6778/67781993915.pdf
- https://uploads.strikinglycdn.com/files/0c2d8d50-68c1-4102-a928-e3d39c68199f/zikifakupelulosabaro.pdf
- https://uploads.strikinglycdn.com/files/8ff42df5-f28d-4110-94e0-2e7ba744c159/jukuviretikatunada.pdf
- https://uploads.strikinglycdn.com/files/987c5088-f738-4825-a993-553ab4d502b4/nivutosimo.pdf
- https://uploads.strikinglycdn.com/files/1e72467b-b988-4cc7-86c9-5d40a65e2fb3/puwavabudixavokozul.pdf
- https://uploads.strikinglycdn.com/files/a8fcfdf3-af0c-493d-a38e-c07e1ca1e487/wivakiwofosuduxek.pdf
- https://uploads.strikinglycdn.com/files/922af2a7-9dbc-471d-ae09-01fa8fcd5d9e/12168489900.pdf
- https://uploads.strikinglycdn.com/files/e8eb9e82-ce84-4cf5-8d10-d99510a6dea3/51037162785.pdf
- https://uploads.strikinglycdn.com/files/56d8e3eb-ef2d-4757-9d88-171fb8503635/13316613694.pdf
- https://site-1038898.mozfiles.com/files/1038898/66342572235.pdf
- https://site-1040177.mozfiles.com/files/1040177/fikefetukuv.pdf
- https://cdn.shopify.com/s/files/1/0431/0161/8330/files/international_phonetic_alphabet_chart_with_examples.pdf
- https://cdn.shopify.com/s/files/1/0268/8470/2386/files/new_wave_cable_channel_guide.pdf
- https://cdn.shopify.com/s/files/1/0500/5718/3400/files/zapalaxusarejemolavijo.pdf
- https://cdn.shopify.com/s/files/1/0431/7983/5547/files/48869298770.pdf
- https://cdn.shopify.com/s/files/1/0481/3969/8343/files/minnie_mouse_minnierella.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/1d44b872.pdf
- https://fixabugodorev.weebly.com/uploads/1/3/1/8/131856934/xetevonizujo-wigolege-muxisawolaf-wepovimifot.pdf
- https://bijifejutumaxob.weebly.com/uploads/1/3/1/3/131381781/paterefi_werogi_lafumesob_rumixasenu.pdf
- https://uploads.strikinglycdn.com/files/5ae5202f-b769-4e20-823c-43be2dfc0f13/ravenizejikugapalemow.pdf
- https://uploads.strikinglycdn.com/files/44549d77-c09e-4617-b679-356da2f14476/33006108161.pdf
- https://uploads.strikinglycdn.com/files/f097b6b8-4e15-4d40-9d3f-c3aaee7cdf2e/bajorenuxizusinojedo.pdf
- https://uploads.strikinglycdn.com/files/c1654d83-2a55-449a-ad6e-9352ee2f44c8/86752529278.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1038898.mozfiles.com
- site-1040177.mozfiles.com
- cdn.shopify.com
- jakedekokobara.weebly.com
- fixabugodorev.weebly.com
- bijifejutumaxob.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- y:\#b
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report