SUSPICIOUS — lenikeboxi_mipokezimon.pdf
SUSPICIOUS — lenikeboxi_mipokezimon.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
39a634f21c2f04dc181d7ffd37b10958652acef7d09ebbddf6843987e255712f - SHA-1:
8c57bd4181cf5855735104d1c3ca14d5a42ef18f - MD5:
a08238299e9a49bd67d158e04bb50bf1 - ssdeep:
768:fgGzpDQpJyJHVGFUJdLaqY74es0q2yeGjLHyqwKkb8UwiYwvd2HnAD1leH50:oGFMpsa5R/q2ynjjR1HiYYdkn41leH50 - TLSH:
T166329EF75093FD8CBF8FAF039EEB0159918AD748A03696905898762CC17CAED7D00661 - Submitted as: lenikeboxi_mipokezimon.pdf
- File type: pdf · Size: 45450 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=star%20wars%20song%20violin%20sheet%20music, https://cdn.shopify.com/s/files/1/0465/2780/7646/files/10639195001.pdf, https://cdn.shopify.com/s/files/1/0496/4027/6131/files/free_tinder_gold_trial.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=star%20wars%20song%20violin%20sheet%20music
- https://cdn.shopify.com/s/files/1/0465/2780/7646/files/10639195001.pdf
- https://cdn.shopify.com/s/files/1/0496/4027/6131/files/free_tinder_gold_trial.pdf
- https://cdn.shopify.com/s/files/1/0499/8440/5666/files/babies_cant_wait_speech_therapy.pdf
- https://cdn.shopify.com/s/files/1/0483/4695/5927/files/9959207979.pdf
- https://cdn-cms.f-static.net/uploads/4366982/normal_5f8782e04832c.pdf
- https://uploads.strikinglycdn.com/files/2e81fb16-9a05-4a59-8866-ae9c6c91ff84/rubukozitobibimopapaxanik.pdf
- https://uploads.strikinglycdn.com/files/b34e0b4d-798d-414a-84f1-19e148365365/35110409226.pdf
- https://uploads.strikinglycdn.com/files/9bc05feb-376c-40f0-8244-930737a176c8/pozepuwafikasumemipomasuw.pdf
- https://uploads.strikinglycdn.com/files/351acf5b-12f4-44ff-8e0d-a551f77de10d/bukuzojeso.pdf
- https://uploads.strikinglycdn.com/files/d777d40b-2821-4b57-aaff-539b59373d91/wefojixojofeminevokavo.pdf
- https://site-1037275.mozfiles.com/files/1037275/81797406334.pdf
- https://site-1039668.mozfiles.com/files/1039668/vamoforapozetasuzidijejev.pdf
- https://site-1040669.mozfiles.com/files/1040669/31038873369.pdf
- https://site-1036944.mozfiles.com/files/1036944/60054950525.pdf
- https://rewemekekebaz.weebly.com/uploads/1/3/1/4/131406535/6578987.pdf
- https://kekerisasil.weebly.com/uploads/1/3/0/7/130775365/29973.pdf
- https://tenagudewujuga.weebly.com/uploads/1/3/1/1/131164273/sipab.pdf
- https://rabexowubomisuw.weebly.com/uploads/1/3/1/4/131407155/0b296aa39bf.pdf
- https://dirigesibujov.weebly.com/uploads/1/3/0/9/130969991/4078745.pdf
- https://uploads.strikinglycdn.com/files/5258ffd0-7472-4b5e-a72f-df360eb8d956/80386446189.pdf
- https://uploads.strikinglycdn.com/files/dfd484e6-64b3-4726-a290-040fcce3914d/nudebufetolowumufutowe.pdf
- https://uploads.strikinglycdn.com/files/4e3d54e3-0c02-44fc-a13d-d1aaaebb92b2/popijiniduxadiv.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1037275.mozfiles.com
- site-1039668.mozfiles.com
- site-1040669.mozfiles.com
- site-1036944.mozfiles.com
- rewemekekebaz.weebly.com
- kekerisasil.weebly.com
- tenagudewujuga.weebly.com
- rabexowubomisuw.weebly.com
- dirigesibujov.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report