SUSPICIOUS — makik_pavuvaxefi_dinimitogo.pdf
SUSPICIOUS — makik_pavuvaxefi_dinimitogo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
28a5cd28cb1f2e2b66b02e1ddac77e759a06617cd732f204756d589870d927b5 - SHA-1:
1f6f220f652ded73b68251cd4267b9a025374efd - MD5:
0622f76bd6165df94998b058e7bd1c87 - ssdeep:
768:3gGzpDJS9lO5MCsAXBOtkcnIH/4JSV+u+NCfE:QGFFV5b/OkcIH/4JSwu+NCfE - TLSH:
T197318DF34097DC8C2A9B6F076EA71098A445D7CC6033A7A01984B73D80BCAFD7E11A65 - Submitted as: makik_pavuvaxefi_dinimitogo.pdf
- File type: pdf · Size: 40658 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://traffmen.ru/wb?keyword=david%20birdsall%20farrier, https://vukibawurop.weebly.com/uploads/1/3/4/6/134601902/tesefewogakusep-gapewesug-kutivuxanalobi-retokokekepug.pdf, https://fetofopup.weebly.com/uploads/1/3/4/5/134507679/5ca493e4706.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffmen.ru/wb?keyword=david%20birdsall%20farrier
- https://vukibawurop.weebly.com/uploads/1/3/4/6/134601902/tesefewogakusep-gapewesug-kutivuxanalobi-retokokekepug.pdf
- https://fetofopup.weebly.com/uploads/1/3/4/5/134507679/5ca493e4706.pdf
- https://uploads.strikinglycdn.com/files/36255651-049f-4d16-8c4f-e55730918765/81572391937.pdf
- https://rosotomana.weebly.com/uploads/1/3/4/5/134585450/serupew.pdf
- https://uploads.strikinglycdn.com/files/24de8cae-21ca-4004-af4c-9e9d0a2f6181/pisaxovawufoxevorenobe.pdf
- https://uploads.strikinglycdn.com/files/cf5f675b-e4ef-47cd-9c2d-b132b8d35064/35724572967.pdf
- https://s3.amazonaws.com/mexavofezoxi/situn.pdf
- https://tokitowopune.weebly.com/uploads/1/3/4/4/134498993/mowojomudajepofap.pdf
- https://s3.amazonaws.com/bitizopovopaso/bsc_3rd_year_botany_notes.pdf
- https://uploads.strikinglycdn.com/files/3e3ea3eb-da79-4be7-a855-ad421a8c4f89/budotuwetel.pdf
- https://s3.amazonaws.com/xanebavifamopez/97966436129.pdf
- https://s3.amazonaws.com/libowebujakux/tilitofatifeligeka.pdf
- https://s3.amazonaws.com/wexukufedepim/coraline_book_download.pdf
- https://uploads.strikinglycdn.com/files/c59427e1-7ffe-471d-9ca8-8173919db3cf/27496258094.pdf
- https://s3.amazonaws.com/kavitokolezub/99980710751.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffmen.ru
- vukibawurop.weebly.com
- fetofopup.weebly.com
- uploads.strikinglycdn.com
- rosotomana.weebly.com
- s3.amazonaws.com
- tokitowopune.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report