SUSPICIOUS — mimeviku.pdf
SUSPICIOUS — mimeviku.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e7ced705e016011f62e96ff58cc4320f3418861f81e1f36b555654cfd685938d - SHA-1:
af362c64f9dab740da0f4be899e71bcc05846cfd - MD5:
e49eacb40c018e6f62d9a07a64e85825 - ssdeep:
768:JgGzpDDWraLybBpoIW/esDxuw3Un4jkrqsj6P9qmWDxwr6opgwrlAsw:qGFP92DW/hDrE4lsO1q3Vwr6ovlAsw - TLSH:
T10234BFF31087DDCC69CAEF1369B71565A10AC6487233A654658CB63CC87C6FCADA09B0 - Submitted as: mimeviku.pdf
- File type: pdf · Size: 54859 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/3aa7f984-4106-4d83-803f-677b811f45ec/41411941700.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=guitar+chords+lesson+pdf, http://files.elizabethmenninga.com/uploads/1/3/0/8/130814411/1c72d475d9.pdf, http://files.dixieautosalvage.com/uploads/1/3/0/8/130814254/gumelorok_nibofo_jofalujuved.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=guitar+chords+lesson+pdf
- http://files.elizabethmenninga.com/uploads/1/3/0/8/130814411/1c72d475d9.pdf
- http://files.dixieautosalvage.com/uploads/1/3/0/8/130814254/gumelorok_nibofo_jofalujuved.pdf
- http://porod.venetoreview.com/uploads/1/3/0/8/130814687/gudifiwowir.pdf
- https://uploads.strikinglycdn.com/files/3aa7f984-4106-4d83-803f-677b811f45ec/41411941700.pdf
- https://uploads.strikinglycdn.com/files/51bc21b3-5bf0-4acd-9b32-d78e49d10fec/dasatanewoveziwibo.pdf
- https://uploads.strikinglycdn.com/files/7cd9112d-0539-46a8-829d-ab5c202ee638/kisanarasolitigesev.pdf
- https://cdn.shopify.com/s/files/1/0437/5920/6561/files/damutupijigozitetezev.pdf
- https://cdn.shopify.com/s/files/1/0428/9835/8432/files/37237973095.pdf
- https://cdn.shopify.com/s/files/1/0432/2036/9567/files/mafia_city_hack.pdf
- https://uploads.strikinglycdn.com/files/17774a77-1c13-4cd0-b478-caab9f810acc/jamisirogunabesoxagadeda.pdf
- https://uploads.strikinglycdn.com/files/1fa085ff-8baf-4325-933c-ec868f84214e/dutofikubafi.pdf
- https://uploads.strikinglycdn.com/files/deadf61c-6cdd-4939-911f-0ee992fea35e/1595322895.pdf
- https://uploads.strikinglycdn.com/files/caaa52d7-13a3-460c-ba22-7db33b7d8a9b/lovuriwarevitifet.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- files.elizabethmenninga.com
- files.dixieautosalvage.com
- porod.venetoreview.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report