SUSPICIOUS — birilajemibewa.pdf
SUSPICIOUS — birilajemibewa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
efb67035b48bd42229ba9ddd19eff4210efbf98272f1173f2da60247cc655a8c - SHA-1:
a4251121ea527a83f01ba57fef8d5b8fb6fc6d13 - MD5:
1cba654f79578bfad6955964d3333549 - ssdeep:
768:TRgGzpDmp833MFsxIpjkAogaRljZzMEHxwsOFslMPp4h9kEox+rYecqkfuM+:TiGFap83wGZzjOsOFslU4h3ox+rAuM+ - TLSH:
T17632AEF31093DD4C7ACAAB13ADEB11AA618DC64CA127D7A019DC375CC4BC56DAD108A2 - Submitted as: birilajemibewa.pdf
- File type: pdf · Size: 46918 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/9f4888a9-306a-47e4-b6bf-66f260234cbf/zidekunakexelut.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=best%20barrel%20length%20for%20224%20valkyrie, https://baletepo.weebly.com/uploads/1/3/0/7/130776023/b7f598ab9f6f7.pdf, https://wetuxabo.weebly.com/uploads/1/3/0/8/130873937/6d7297.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=best%20barrel%20length%20for%20224%20valkyrie
- https://baletepo.weebly.com/uploads/1/3/0/7/130776023/b7f598ab9f6f7.pdf
- https://wetuxabo.weebly.com/uploads/1/3/0/8/130873937/6d7297.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/nerato_dedamelaniris_majokugotigoj.pdf
- https://kufazijofiw.weebly.com/uploads/1/3/0/7/130776126/jujakurubujozigobo.pdf
- https://cdn.shopify.com/s/files/1/0492/4512/6812/files/kein_ort_ohne_dich_ganzer_film_stream.pdf
- https://cdn.shopify.com/s/files/1/0484/7953/5258/files/91418333965.pdf
- https://cdn.shopify.com/s/files/1/0491/8326/0838/files/samsung_microwave_manual_me21r7051ss.pdf
- https://cdn.shopify.com/s/files/1/0437/9262/9917/files/paluw.pdf
- https://uploads.strikinglycdn.com/files/9f4888a9-306a-47e4-b6bf-66f260234cbf/zidekunakexelut.pdf
- https://uploads.strikinglycdn.com/files/5037b2b5-12b8-4081-94df-be98257c0c7f/95630925769.pdf
- https://uploads.strikinglycdn.com/files/256b07c7-dc6f-4b07-ad54-46bb9b7d14bb/lekegovegofeku.pdf
- https://cdn.shopify.com/s/files/1/0481/5916/2521/files/carrinho_chicco_ohlala_manual.pdf
- https://cdn.shopify.com/s/files/1/0492/3827/8300/files/77500237453.pdf
- https://cdn.shopify.com/s/files/1/0499/1893/5208/files/91882762043.pdf
- https://cdn.shopify.com/s/files/1/0432/5087/6578/files/zejuliwip.pdf
- https://cdn.shopify.com/s/files/1/0500/9906/0904/files/words_starting_with_dr.pdf
- https://uploads.strikinglycdn.com/files/9c87cb44-0488-4705-af0e-6e49f231bebb/77810835612.pdf
- https://uploads.strikinglycdn.com/files/78544918-761e-43bc-87ba-39549ecff72e/padizabutelulepedenifaxek.pdf
- https://uploads.strikinglycdn.com/files/f56fd8f2-67b5-4fb9-85cd-849608664ef6/tujefebemini.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- baletepo.weebly.com
- wetuxabo.weebly.com
- xojerajap.weebly.com
- kufazijofiw.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report