SUSPICIOUS — muvivafejux-dawexarozawos-misilidasojix-novogezejixaxav.pdf
SUSPICIOUS — muvivafejux-dawexarozawos-misilidasojix-novogezejixaxav.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
86437514501f06c14b6045c9e1653333ad07d8e91e23919bd79866b5d5720b51 - SHA-1:
f5c3c641d495cf2f5262ed0a0dbd4a898a8de059 - MD5:
4cb693f2a285d8f223fb78ade1abedd0 - ssdeep:
768:fgGzpDm2gXO6wWYKgw/XaGp0/simte7UWkVmv13yOkB8zm3rw5ejRjtbRlwV5:oGFq6WsuHM7UxVmv5y/B8zm3rwyJRuV5 - TLSH:
T19032BFF35197CD4CFAC69B139DE60029204BC74C71329AE089DCBB6C85B86ECBE40961 - Submitted as: muvivafejux-dawexarozawos-misilidasojix-novogezejixaxav.pdf
- File type: pdf · Size: 45711 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/3905af03-b6b6-435a-aeba-09933f21e5b1/diablo_2_dupe_method.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://trafftec.ru/wb?keyword=nordictrack%20treadmill%20repairs, https://kelobutino.weebly.com/uploads/1/3/0/9/130969458/6977354.pdf, https://rexolofozex.weebly.com/uploads/1/3/4/3/134368018/bikirutinekekix-bemot.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafftec.ru/wb?keyword=nordictrack%20treadmill%20repairs
- https://kelobutino.weebly.com/uploads/1/3/0/9/130969458/6977354.pdf
- https://rexolofozex.weebly.com/uploads/1/3/4/3/134368018/bikirutinekekix-bemot.pdf
- https://cdn-cms.f-static.net/uploads/4389830/normal_5fa24e093a133.pdf
- https://cdn-cms.f-static.net/uploads/4392195/normal_5f9cf7103a20b.pdf
- https://cdn-cms.f-static.net/uploads/4366327/normal_5f9867df264e6.pdf
- https://cdn-cms.f-static.net/uploads/4468820/normal_5fa6068f83312.pdf
- https://uploads.strikinglycdn.com/files/3905af03-b6b6-435a-aeba-09933f21e5b1/diablo_2_dupe_method.pdf
- https://uploads.strikinglycdn.com/files/2c5bfdd3-d594-4612-b7e7-0876d631a651/eso_motif_prices.pdf
- https://cdn-cms.f-static.net/uploads/4417543/normal_5fa2593403641.pdf
- https://cdn-cms.f-static.net/uploads/4382631/normal_5fa5f4565268d.pdf
- https://uploads.strikinglycdn.com/files/293350ab-1db8-4bc4-be36-8dbd06083e44/69723400950.pdf
- https://wevinavuligi.weebly.com/uploads/1/3/4/5/134505150/df4bd34a0c50.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafftec.ru
- kelobutino.weebly.com
- rexolofozex.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- wevinavuligi.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report