SUSPICIOUS — monujetepagelekakax.pdf
SUSPICIOUS — monujetepagelekakax.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0a7d58dd6ffb1934e5b7806a99d95c3ec0eccfea3572d644787f9e1fd4aaf526 - SHA-1:
bddc1fdf6a0a0b55823923f62066e81b5dd7aa18 - MD5:
c54f97e4c00b494c240f59e4bd9c2928 - ssdeep:
768:HgGzpDJpclR1vUAPduZPwOEU+H62Fj9jrjw79kNtVjafnws5VoTn38tHjA66:AGF9pcHRrI6Nj2rVoTMtDA66 - TLSH:
T15432AFF350A7ED8C7B8B6B07A9E7116A5145C38DA13697A04598772CD0BC37DBE00CA1 - Submitted as: monujetepagelekakax.pdf
- File type: pdf · Size: 46255 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/6d5a3f07-735a-431a-97a1-ce2b4de3e4ac/90128404447.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=bandicut%20video%20cutter, https://site-1044155.mozfiles.com/files/1044155/convict_conditioning_progressions.pdf, https://site-1038482.mozfiles.com/files/1038482/27800918171.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=bandicut%20video%20cutter
- https://site-1044155.mozfiles.com/files/1044155/convict_conditioning_progressions.pdf
- https://site-1038482.mozfiles.com/files/1038482/27800918171.pdf
- https://site-1042684.mozfiles.com/files/1042684/rolepegekewa.pdf
- https://uploads.strikinglycdn.com/files/6d5a3f07-735a-431a-97a1-ce2b4de3e4ac/90128404447.pdf
- https://uploads.strikinglycdn.com/files/52ebf649-5626-4c34-b6c6-dd900f40af51/xurogodalupegelurifisikib.pdf
- https://uploads.strikinglycdn.com/files/1bf55225-538b-4db1-a37f-39124da19504/tupuvurekixalifoxigix.pdf
- https://uploads.strikinglycdn.com/files/ff762271-2bcf-4099-95d3-3e831fb9cf8b/67519582836.pdf
- https://cdn.shopify.com/s/files/1/0500/0029/8144/files/78027073090.pdf
- https://cdn.shopify.com/s/files/1/0437/1231/5545/files/vemajarubimusaguse.pdf
- https://cdn.shopify.com/s/files/1/0502/9022/9413/files/doguzekipum.pdf
- https://cdn.shopify.com/s/files/1/0483/5753/9989/files/aimpoint_micro_t-1_tarkov.pdf
- https://cdn.shopify.com/s/files/1/0493/7252/8799/files/primavera_p6_8.1_installation_guide.pdf
- https://uploads.strikinglycdn.com/files/82eb4166-821d-460f-9059-d6e7911f9745/levuzixelipidepadi.pdf
- https://uploads.strikinglycdn.com/files/600bbfea-4077-45ee-bfd2-8647f723dce5/95662609226.pdf
- https://uploads.strikinglycdn.com/files/517f27f8-96bb-4ed9-af32-6d703e0cb8be/47904327544.pdf
- https://cdn.shopify.com/s/files/1/0497/4660/8282/files/jifuwegoxef.pdf
- https://cdn.shopify.com/s/files/1/0430/2936/4899/files/mozarabic_chronicle_text.pdf
- https://cdn.shopify.com/s/files/1/0498/3819/4843/files/12646923178.pdf
- https://cdn.shopify.com/s/files/1/0483/2464/0932/files/flash_games_2020_download.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- site-1044155.mozfiles.com
- site-1038482.mozfiles.com
- site-1042684.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report