SUSPICIOUS — muvukiru.pdf
SUSPICIOUS — muvukiru.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b56804606f7c6ad729ab4fdb92e46f1c272ce904c0274a268f7e75764b025ddc - SHA-1:
894707430b131f3472a4a3fee43552266c404b29 - MD5:
bbc64a881d4b9f2ae4c0b0f91ee0936f - ssdeep:
768:igGzpD/p79ZQN++D4LjXgHSjuNUlLribmejLAE3vEZFXtPqpQho4d:/GFzpYrDaXgH21rxejLAE/EztSGho4d - TLSH:
T139319DF354A7DC8C3A8BAB135EA60049629AC78D7237A7A0059C777CC87C1BD6F50861 - Submitted as: muvukiru.pdf
- File type: pdf · Size: 43167 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/ca1220b3-3f9f-4e46-8419-4ebd7cc004f3/43782365737.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=fallout+new+vegas+4gb+patcher+nvse, https://uploads.strikinglycdn.com/files/ca1220b3-3f9f-4e46-8419-4ebd7cc004f3/43782365737.pdf, https://uploads.strikinglycdn.com/files/83bc02c2-350d-41ed-9a75-6481c7cb0769/82713143400.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=fallout+new+vegas+4gb+patcher+nvse
- https://uploads.strikinglycdn.com/files/ca1220b3-3f9f-4e46-8419-4ebd7cc004f3/43782365737.pdf
- https://uploads.strikinglycdn.com/files/83bc02c2-350d-41ed-9a75-6481c7cb0769/82713143400.pdf
- https://uploads.strikinglycdn.com/files/45243384-a25b-4991-ae0a-d27ce78bbf6f/zokuwonorewa.pdf
- https://uploads.strikinglycdn.com/files/a9f93e78-655c-4a79-8e5f-64031723cd21/sivodugu.pdf
- https://uploads.strikinglycdn.com/files/b7f0442b-ee9d-47ec-bf45-175a17e4c00c/94987448649.pdf
- http://files.gamain.gaflint.org/uploads/1/3/1/3/131383775/9bf510b26cc.pdf
- http://files.bentnorthrop.org/uploads/1/3/0/7/130739488/pizisipujatag-givuza.pdf
- http://files.ksasteel.com/uploads/1/3/2/7/132740620/8befd.pdf
- https://site-1043491.mozfiles.com/files/1043491/vewanakaji.pdf
- https://site-1039875.mozfiles.com/files/1039875/bajaposuxipivop.pdf
- https://site-1037866.mozfiles.com/files/1037866/papamapo.pdf
- https://site-1042452.mozfiles.com/files/1042452/kolenifatezudune.pdf
- https://site-1037260.mozfiles.com/files/1037260/kuretodajabagorotak.pdf
- https://site-1039560.mozfiles.com/files/1039560/rudavokezibukazed.pdf
- https://site-1040298.mozfiles.com/files/1040298/83525117965.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- files.gamain.gaflint.org
- files.bentnorthrop.org
- files.ksasteel.com
- site-1043491.mozfiles.com
- site-1039875.mozfiles.com
- site-1037866.mozfiles.com
- site-1042452.mozfiles.com
- site-1037260.mozfiles.com
- site-1039560.mozfiles.com
- site-1040298.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report