SUSPICIOUS — mafisomese_gajifozigu.pdf
SUSPICIOUS — mafisomese_gajifozigu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f3170f8cfffe2598fed0e9fe83929c3a6065facb2984d2b69222f58201c09bac - SHA-1:
1d1881a91681194a3ea1f517faaa592237462198 - MD5:
15a8cdb692752b82c0a80d3a5481843d - ssdeep:
768:SJgGzpDnp0UWo+yNJl/w4Z+OIjE/1hSd5dAkqjQ1QhaahTCnXk1P0jKFyB:lGFbpZ/1hSdLWIuTCnXkUK4B - TLSH:
T153329EF30067ED8C3BCACB03ADE715566549DB496037E7A418996B6CC8AC67D7E10C20 - Submitted as: mafisomese_gajifozigu.pdf
- File type: pdf · Size: 44745 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://jamafijuzu.weebly.com/uploads/1/3/1/4/131437216/jejuroletadodufana.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=calculus%20early%20transcendentals%20pearson%20new%20international%20edition%20pdf, https://jamafijuzu.weebly.com/uploads/1/3/1/4/131437216/jejuroletadodufana.pdf, https://nefenupenarus.weebly.com/uploads/1/3/4/4/134476068/3aa6c5.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=calculus%20early%20transcendentals%20pearson%20new%20international%20edition%20pdf
- https://jamafijuzu.weebly.com/uploads/1/3/1/4/131437216/jejuroletadodufana.pdf
- https://nefenupenarus.weebly.com/uploads/1/3/4/4/134476068/3aa6c5.pdf
- https://lenololiwi.weebly.com/uploads/1/3/4/4/134455370/1965161.pdf
- https://xusawoji.weebly.com/uploads/1/3/0/7/130739635/kaleb.pdf
- https://vewutaniwem.weebly.com/uploads/1/3/0/8/130873717/6f0a2c.pdf
- https://cdn.shopify.com/s/files/1/0430/7084/9181/files/pedazodesepogegamata.pdf
- https://cdn.shopify.com/s/files/1/0432/9383/5432/files/heroes_evolved_hack_android.pdf
- https://cdn.shopify.com/s/files/1/0437/0956/3035/files/1694757734.pdf
- https://cdn.shopify.com/s/files/1/0434/0901/4940/files/24540807615.pdf
- https://cdn.shopify.com/s/files/1/0485/6794/3328/files/59119178376.pdf
- https://cdn.shopify.com/s/files/1/0441/3105/7816/files/teaching_conversational_english_lesson_plans.pdf
- https://cdn.shopify.com/s/files/1/0438/9706/1531/files/malinagawo.pdf
- https://cdn-cms.f-static.net/uploads/4366377/normal_5f872280bfa1e.pdf
- https://cdn-cms.f-static.net/uploads/4365541/normal_5f8788fbbba85.pdf
- https://cdn-cms.f-static.net/uploads/4373239/normal_5f951cd80972a.pdf
- https://cdn-cms.f-static.net/uploads/4372358/normal_5f94286450baa.pdf
- https://cdn-cms.f-static.net/uploads/4401559/normal_5f90a7c4f0e72.pdf
- https://vopevejefed.weebly.com/uploads/1/3/1/6/131606133/5841c67d8.pdf
- https://putigazabikikim.weebly.com/uploads/1/3/2/6/132682718/kavud_rejidopaveni_nuxujikalobek_virazuzegivuju.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- jamafijuzu.weebly.com
- nefenupenarus.weebly.com
- lenololiwi.weebly.com
- xusawoji.weebly.com
- vewutaniwem.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- vopevejefed.weebly.com
- putigazabikikim.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report