SUSPICIOUS — vabevoxemupovivaje.pdf
SUSPICIOUS — vabevoxemupovivaje.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
33d622a1fc9e1e154b76cc4485ab31c54fe04be88d4bacc99f19a7877449a867 - SHA-1:
837f0fda3b9042b783ebb8b3f1089a1c01b585eb - MD5:
940a89862fd60b58d7e35a516eb03712 - ssdeep:
768:xgGzpDUpDox0xKrow8lJfLbk3/cZID+D1fepBbybXaUDDr4SbCX0ISUNqmauGeFK:CGFgpExTsKp0CqmKeSNn - TLSH:
T1F9339EF310A7DC4D7A8B2F43AEAB169A608DD348612BDB50508C7B2DD07C6FD2E50A51 - Submitted as: vabevoxemupovivaje.pdf
- File type: pdf · Size: 50981 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://lagukekejase.weebly.com/uploads/1/3/0/8/130815031/ecea2be33.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=dixit%20rules%20pdf, https://cdn-cms.f-static.net/uploads/4375690/normal_5f8c609c8d3f3.pdf, https://cdn-cms.f-static.net/uploads/4366014/normal_5f888c01a40cd.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=dixit%20rules%20pdf
- https://cdn-cms.f-static.net/uploads/4375690/normal_5f8c609c8d3f3.pdf
- https://cdn-cms.f-static.net/uploads/4366014/normal_5f888c01a40cd.pdf
- https://cdn-cms.f-static.net/uploads/4366000/normal_5f8a710c543e5.pdf
- https://cdn-cms.f-static.net/uploads/4366305/normal_5f87655deea1c.pdf
- https://zegojipoxe.weebly.com/uploads/1/3/1/0/131069766/venitox-nukitixezak.pdf
- https://lagukekejase.weebly.com/uploads/1/3/0/8/130815031/ecea2be33.pdf
- https://cdn.shopify.com/s/files/1/0481/7213/8663/files/18442356883.pdf
- https://cdn.shopify.com/s/files/1/0440/7725/2760/files/ron_atkinson_family.pdf
- https://cdn.shopify.com/s/files/1/0429/7680/5023/files/48137806863.pdf
- https://cdn.shopify.com/s/files/1/0483/4770/9591/files/dosabafabefozo.pdf
- https://cdn.shopify.com/s/files/1/0462/3866/2807/files/china_through_the_looking_glass.pdf
- https://cdn-cms.f-static.net/uploads/4366337/normal_5f8d8927c9fe0.pdf
- https://cdn-cms.f-static.net/uploads/4370561/normal_5f89946116c50.pdf
- https://cdn-cms.f-static.net/uploads/4366637/normal_5f8a5c81a0512.pdf
- https://cdn-cms.f-static.net/uploads/4366405/normal_5f8c87ad4c2f0.pdf
- https://cdn-cms.f-static.net/uploads/4366044/normal_5f86f82adebc0.pdf
- https://uploads.strikinglycdn.com/files/b35b3054-ad9d-414a-9e48-a4028b0b53e9/wunalunuvekenofesatubefo.pdf
- https://uploads.strikinglycdn.com/files/476fe6f1-8886-4b07-9ea2-e4b54810f980/58372261093.pdf
- https://uploads.strikinglycdn.com/files/0e32e156-f42d-4711-a49c-20fc02ccf36e/35803454118.pdf
- https://uploads.strikinglycdn.com/files/85bbb24f-3918-41c4-8ad8-24471e6310c2/xigojumasixodefu.pdf
- https://uploads.strikinglycdn.com/files/245049f7-a386-4b40-ba69-49e69904b9b1/jisadebobipivenedoboxu.pdf
- https://cdn.shopify.com/s/files/1/0268/7936/1212/files/83937803072.pdf
- https://cdn.shopify.com/s/files/1/0266/9068/3069/files/notokukoloforegetujukoliz.pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/turbo_vpn_mod_apk_2.9.5.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- zegojipoxe.weebly.com
- lagukekejase.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report