SUSPICIOUS — melot-zepaxolixotasak-burofuwetiso.pdf
SUSPICIOUS — melot-zepaxolixotasak-burofuwetiso.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f91d7c9fcd4c80415139861f4e40dea487bd8e2e795eb434f3f3e93615f304aa - SHA-1:
8474d91446b24467ac52b800ca5e8d6c611a7275 - MD5:
53f1cc6ea808044e8d31f5d6a3578d22 - ssdeep:
768:9gGzpDSpA7JH9OySHnqrfiS9cXJK2SlWbumEEmhApQ0MaTKvJlsLqsA0rqjW:+GFWp8D9NfFl5aTKR/n0rqjW - TLSH:
T1EA328EF35057ED8C7A4A5F03AEEB24A9655AC34DA1369760048C772CC4BC6FD7E00A92 - Submitted as: melot-zepaxolixotasak-burofuwetiso.pdf
- File type: pdf · Size: 47470 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/60a0fc5b-c669-410e-9e6d-255cc7e8f148/les_mordus_du_galets.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=bedroom%20design%20pdf, https://uploads.strikinglycdn.com/files/60a0fc5b-c669-410e-9e6d-255cc7e8f148/les_mordus_du_galets.pdf, https://uploads.strikinglycdn.com/files/1ba38945-ad6a-4fd4-8ede-cb1c7367fb48/sasoxuvesifuri.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=bedroom%20design%20pdf
- https://uploads.strikinglycdn.com/files/60a0fc5b-c669-410e-9e6d-255cc7e8f148/les_mordus_du_galets.pdf
- https://uploads.strikinglycdn.com/files/1ba38945-ad6a-4fd4-8ede-cb1c7367fb48/sasoxuvesifuri.pdf
- https://uploads.strikinglycdn.com/files/ea12a9b2-492d-4d2f-afd4-159d76de7b5e/92661316556.pdf
- https://uploads.strikinglycdn.com/files/2b548a8d-9fde-4a5f-9713-7fd067d9bfd1/bojisigigafus.pdf
- https://uploads.strikinglycdn.com/files/96187ff2-0c93-4662-951a-6893c89d8ad4/76661456386.pdf
- https://jovikuveditowe.weebly.com/uploads/1/3/0/8/130874612/d3e4ca9503a7.pdf
- https://cdn.shopify.com/s/files/1/0503/3879/1582/files/wogovojemamagi.pdf
- https://cdn.shopify.com/s/files/1/0440/3950/4022/files/wopol.pdf
- https://cdn.shopify.com/s/files/1/0266/9468/0775/files/vixake.pdf
- https://cdn.shopify.com/s/files/1/0502/7486/1250/files/suits_season_7_episode_guide_tv.com.pdf
- https://cdn.shopify.com/s/files/1/0502/8125/0988/files/myocardial_infarction_guidelines_icd_10.pdf
- https://cdn-cms.f-static.net/uploads/4374178/normal_5f89f3a9bef37.pdf
- https://cdn-cms.f-static.net/uploads/4368736/normal_5f8b7ca557724.pdf
- https://s3.amazonaws.com/henghuili-files2/lubowijele.pdf
- https://s3.amazonaws.com/dejolavubukugeb/dimajode.pdf
- https://s3.amazonaws.com/jamokaroxoj/753225628.pdf
- https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/6670345ba.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/gevoderovepiru.pdf
- https://zafozudakajadev.weebly.com/uploads/1/3/0/8/130814863/b628c54eef4e3.pdf
- https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/6a546ab710.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- jovikuveditowe.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- babikovinemixe.weebly.com
- jawasolasazilem.weebly.com
- zafozudakajadev.weebly.com
- sesuwulot.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report