SUSPICIOUS — mujopagud_tidimixepikix_vipozakimipimi_belis.pdf
SUSPICIOUS — mujopagud_tidimixepikix_vipozakimipimi_belis.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b51e7c945c81be9fef2fd56e020ffdc336d4d23b381b6a61d82402b0d07361e3 - SHA-1:
80b19cb6143e9c36886fad25513282bacaff762a - MD5:
2a9dee4a5c99c3a28a88d38086fcd4eb - ssdeep:
1536:nGFEpN6AmrFDFYcJvuDWIsuMAv7GLqt1s7IBT8j/s5wBp2v5QsqjLtiq:GFEpAA2kQuDWIGKw8i0BM/Ywj2v5r8N - TLSH:
T1ED39C0F39057DD0CBAC79F43AAA6295AA15AC78C2132976054CDBB2CC4B83FC2F51560 - Submitted as: mujopagud_tidimixepikix_vipozakimipimi_belis.pdf
- File type: pdf · Size: 86171 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/d3b0cd8a-4c94-4da9-ad19-0fac9fc3bac1/80146886594.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=skyrim%20legendary%20edition%20update%2013%20d, https://cdn-cms.f-static.net/uploads/4367937/normal_5f876d2f79c7f.pdf, https://cdn-cms.f-static.net/uploads/4366401/normal_5f8727447e88a.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=skyrim%20legendary%20edition%20update%2013%20d
- https://cdn-cms.f-static.net/uploads/4367937/normal_5f876d2f79c7f.pdf
- https://cdn-cms.f-static.net/uploads/4366401/normal_5f8727447e88a.pdf
- https://cdn-cms.f-static.net/uploads/4366668/normal_5f872c6e3257b.pdf
- https://cdn-cms.f-static.net/uploads/4366000/normal_5f88013b92339.pdf
- https://cdn-cms.f-static.net/uploads/4365619/normal_5f870cfc085c0.pdf
- https://cdn.shopify.com/s/files/1/0501/1423/2485/files/38368226576.pdf
- https://cdn.shopify.com/s/files/1/0496/6491/7661/files/comment_apprendre_la_guitare_basse.pdf
- https://uploads.strikinglycdn.com/files/d3b0cd8a-4c94-4da9-ad19-0fac9fc3bac1/80146886594.pdf
- https://uploads.strikinglycdn.com/files/80c9f3bf-0cff-4adb-a3cf-3acee6ac9b0a/32811097185.pdf
- https://uploads.strikinglycdn.com/files/266f7ed0-8282-4a0e-b909-6b1caf1c229a/fafidoxapakakowobozuv.pdf
- https://uploads.strikinglycdn.com/files/e73680bd-6d5d-47f3-bcd8-52d63d0e12df/12954771542.pdf
- https://uploads.strikinglycdn.com/files/d6d2143e-0675-4166-bcaf-8b0bf4a74d54/985117592.pdf
- https://uploads.strikinglycdn.com/files/b8b9e0d9-cf10-4617-a158-6c8e6c894e37/zewomadefotinabewewam.pdf
- https://uploads.strikinglycdn.com/files/5accd9c6-57a3-4491-b346-eab1b83b1fc3/zuduvejutupid.pdf
- https://uploads.strikinglycdn.com/files/f77eb528-0daf-4374-af67-88cb39777021/27266569978.pdf
- https://cdn-cms.f-static.net/uploads/4366048/normal_5f875251587f8.pdf
- https://cdn-cms.f-static.net/uploads/4367281/normal_5f8824ce144c7.pdf
- https://wivupenoremew.weebly.com/uploads/1/3/0/7/130775018/378398.pdf
- https://gusumadanu.weebly.com/uploads/1/3/2/6/132695601/nogewamuvuzoli-kadujuzusuzo-jagebepazo-faposu.pdf
- https://fimozafovobas.weebly.com/uploads/1/3/2/7/132741130/e12bea6.pdf
- https://lodirunesu.weebly.com/uploads/1/3/0/8/130874391/pigizun.pdf
- https://lasajiboz.weebly.com/uploads/1/3/1/3/131379041/df50809260b9.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- wivupenoremew.weebly.com
- gusumadanu.weebly.com
- fimozafovobas.weebly.com
- lodirunesu.weebly.com
- lasajiboz.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report