SUSPICIOUS — gabevimegupuvun-vunesixoge-nagekenesema.pdf
SUSPICIOUS — gabevimegupuvun-vunesixoge-nagekenesema.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d576d7492f7d9b91eff77ad9fef700fd17b2f7bb6b299844810e7052f21ac163 - SHA-1:
ca95b34ca5973342bf6ecb100e3f90ca536f7107 - MD5:
6e0568b2ce7618345a2cc4bb08f8b702 - ssdeep:
768:IgGzpDppfhOJx27L6nrwYYd8ZXsxEpQzE5wKCHwrW8RF7Ll7uGJ:FGFtpfwcrd8qx1YCHwrVRF7Ll7uGJ - TLSH:
T1B2327BF350A7DC8C7A839B03AEEB255E5159D689613397A548E87B2CC07877C3F10960 - Submitted as: gabevimegupuvun-vunesixoge-nagekenesema.pdf
- File type: pdf · Size: 45055 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://saxexowiki.weebly.com/uploads/1/3/0/9/130969873/9ba2748.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=ftce%20professional%20education%20study%20guide, https://zalawevovupat.weebly.com/uploads/1/3/0/9/130969727/2a1e8a81a94ce7b.pdf, https://saxexowiki.weebly.com/uploads/1/3/0/9/130969873/9ba2748.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=ftce%20professional%20education%20study%20guide
- https://zalawevovupat.weebly.com/uploads/1/3/0/9/130969727/2a1e8a81a94ce7b.pdf
- https://saxexowiki.weebly.com/uploads/1/3/0/9/130969873/9ba2748.pdf
- https://fidegobopoj.weebly.com/uploads/1/3/2/8/132815019/554028.pdf
- https://uploads.strikinglycdn.com/files/d57fc0bf-6a53-40f8-8b24-5a9f2a5826c5/98090121679.pdf
- https://uploads.strikinglycdn.com/files/51cb3ffa-6ae2-464f-9fda-cbbf3a213d96/tasob.pdf
- https://uploads.strikinglycdn.com/files/e39164bf-dfec-4cda-9c6d-14bf3ba0bbfd/kosorexuwitemonuk.pdf
- https://uploads.strikinglycdn.com/files/3c13b31d-76ab-4032-9773-62113857f613/base_dect_livebox.pdf
- https://uploads.strikinglycdn.com/files/bf955ea9-da82-4c0b-a436-50ab06f35464/35451343955.pdf
- https://uploads.strikinglycdn.com/files/d260884b-ce17-4760-83a5-f20b15bae357/blackletter_calligraphy_guide.pdf
- https://uploads.strikinglycdn.com/files/e55f58c9-daee-43d6-8f86-569d4b7de218/jiterijuvo.pdf
- https://cdn.shopify.com/s/files/1/0462/7166/0189/files/vepulata.pdf
- https://cdn.shopify.com/s/files/1/0437/3318/8762/files/ropipegokegujaxafamodamup.pdf
- https://cdn.shopify.com/s/files/1/0484/6996/7013/files/collective_nouns_worksheet_grade_5.pdf
- https://cdn.shopify.com/s/files/1/0498/1859/9579/files/cognos_10_transformer_user_guide.pdf
- https://cdn.shopify.com/s/files/1/0497/1148/0989/files/4398178443.pdf
- https://sepikupi.weebly.com/uploads/1/3/0/7/130738949/154f826c39fded.pdf
- https://rabifupokuwu.weebly.com/uploads/1/3/1/1/131164250/ronununase.pdf
- https://kelobutino.weebly.com/uploads/1/3/0/9/130969458/zegagoragek_nepumudusoku_woguxasar.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- zalawevovupat.weebly.com
- saxexowiki.weebly.com
- fidegobopoj.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- sepikupi.weebly.com
- rabifupokuwu.weebly.com
- kelobutino.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report