SUSPICIOUS — mutapijikokon.pdf
SUSPICIOUS — mutapijikokon.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
1148b969018ee52065dc317527737e1d69a09de9d98d25ab0bef870e22a287dd - SHA-1:
90ea2f01c4d0ed5ef4a89c8434a53dd4e7875bf2 - MD5:
c3f2551247be29e93d629be0de14c3f1 - ssdeep:
768:EgGzpDPL2h+ATbgRi2ECa9xXPns0dYR0ZixkC7UwPSFggt1V96VheICgHLMmQoJD:xGFbLk+ATzCavXvROc1VchzCgMmQZRSD - TLSH:
T16F329DF300A7ED8C7A8BAF13ADEB10566044D78C5172AB90948C3B6CC5BC2BE6E81551 - Submitted as: mutapijikokon.pdf
- File type: pdf · Size: 45313 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=bunny+ears+pattern+free, http://jovexeg.jamie-carl-design.com/uploads/1/3/2/7/132740764/sanogepobede_roruwiti_malupomixozavu.pdf, http://files.adrian-spencer.com/uploads/1/3/1/4/131437318/a65ff2a.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=bunny+ears+pattern+free
- http://jovexeg.jamie-carl-design.com/uploads/1/3/2/7/132740764/sanogepobede_roruwiti_malupomixozavu.pdf
- http://files.adrian-spencer.com/uploads/1/3/1/4/131437318/a65ff2a.pdf
- http://files.coopacabanacochins.com/uploads/1/3/0/7/130740455/1025b17aa.pdf
- http://zuvulawa.oceanassassin.com/uploads/1/3/1/4/131437812/273f15c16b.pdf
- http://files.powertospeaknaked.com/uploads/1/3/2/7/132710671/8872763.pdf
- https://cdn.shopify.com/s/files/1/0483/9758/2494/files/51214250287.pdf
- https://cdn.shopify.com/s/files/1/0432/3724/5086/files/kalelidugujabumobebe.pdf
- https://cdn.shopify.com/s/files/1/0483/2028/2788/files/vaturuduloluforotetikon.pdf
- https://cdn.shopify.com/s/files/1/0500/4047/1702/files/tatesubosepe.pdf
- https://cdn.shopify.com/s/files/1/0433/5465/2822/files/7472421866.pdf
- https://cdn.shopify.com/s/files/1/0480/1527/8239/files/tebozibowa.pdf
- https://cdn.shopify.com/s/files/1/0435/2707/8052/files/majulodiveki.pdf
- https://cdn.shopify.com/s/files/1/0431/5503/0170/files/fazuxidavemikidaxurom.pdf
- https://cdn.shopify.com/s/files/1/0430/2703/8369/files/theyre_playing_with_fire_1984.pdf
- https://cdn.shopify.com/s/files/1/0480/6751/0436/files/fesevidudezuwus.pdf
- http://files.returningtocompassion.org/uploads/1/3/0/7/130740323/9a0ffa3d4.pdf
- http://files.gcchapel.org/uploads/1/3/0/7/130739291/94d9686339d3.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- jovexeg.jamie-carl-design.com
- files.adrian-spencer.com
- files.coopacabanacochins.com
- zuvulawa.oceanassassin.com
- files.powertospeaknaked.com
- cdn.shopify.com
- files.returningtocompassion.org
- files.gcchapel.org
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- r:\XVA+
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report