SUSPICIOUS — zujimixezoruk-xabevopavi-tugegagajerux.pdf
SUSPICIOUS — zujimixezoruk-xabevopavi-tugegagajerux.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a0beea72675660c97bb96cca9413b4181f6b4185f0f8cb1c8d0730c41c833c24 - SHA-1:
8e6bcc1e484fce39dac6d1938ff6f6fbdb920c8c - MD5:
7fe25860479a0f27301aeeb1b2bde77f - ssdeep:
768:GgGzpD3pje9SCgCSJhKwz/rFxibUwxkMQQ/5TJjpV0VMEr+7duNi:TGFrpjeYclb1RTJljK+7duNi - TLSH:
T1912F6CF36097ED8C7ACB9F036EAB1199904AC38CA133966049883A3CD4785FD6F50A51 - Submitted as: zujimixezoruk-xabevopavi-tugegagajerux.pdf
- File type: pdf · Size: 35334 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://natizupasa.weebly.com/uploads/1/3/1/4/131437725/7ecf64b0ccb27b7.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=new%20electronics%20projects%20ideas%20pdf, https://silemixijotin.weebly.com/uploads/1/3/4/4/134463531/pebunevuxe.pdf, https://natizupasa.weebly.com/uploads/1/3/1/4/131437725/7ecf64b0ccb27b7.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=new%20electronics%20projects%20ideas%20pdf
- https://silemixijotin.weebly.com/uploads/1/3/4/4/134463531/pebunevuxe.pdf
- https://natizupasa.weebly.com/uploads/1/3/1/4/131437725/7ecf64b0ccb27b7.pdf
- https://worozimovazez.weebly.com/uploads/1/3/1/4/131406108/wejibogoz.pdf
- https://kekerisasil.weebly.com/uploads/1/3/0/7/130775365/1b97abd629fe14.pdf
- https://cdn.shopify.com/s/files/1/0429/6212/4959/files/hmh_algebra_1.pdf
- https://cdn.shopify.com/s/files/1/0500/6698/1013/files/45035889101.pdf
- https://cdn.shopify.com/s/files/1/0495/6310/7480/files/wuterigilotabe.pdf
- https://cdn.shopify.com/s/files/1/0496/1386/5124/files/23001696489.pdf
- https://vegilirebaj.weebly.com/uploads/1/3/1/0/131070576/7f2b4a6a7222.pdf
- https://pasuliwipo.weebly.com/uploads/1/3/1/4/131452824/votujukitugadep.pdf
- https://mumixopid.weebly.com/uploads/1/3/1/8/131872042/gajozokupezu.pdf
- https://cdn.shopify.com/s/files/1/0500/3021/5317/files/62811136238.pdf
- https://cdn.shopify.com/s/files/1/0498/3298/4731/files/21329251750.pdf
- https://cdn.shopify.com/s/files/1/0500/3735/8742/files/55665748116.pdf
- https://cdn-cms.f-static.net/uploads/4368250/normal_5f8b2cba6f887.pdf
- https://cdn-cms.f-static.net/uploads/4405895/normal_5f9262a118030.pdf
- https://cdn-cms.f-static.net/uploads/4404103/normal_5f960535c2742.pdf
- https://cdn-cms.f-static.net/uploads/4378175/normal_5f8e320590717.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- silemixijotin.weebly.com
- natizupasa.weebly.com
- worozimovazez.weebly.com
- kekerisasil.weebly.com
- cdn.shopify.com
- vegilirebaj.weebly.com
- pasuliwipo.weebly.com
- mumixopid.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report