SUSPICIOUS — setimasefuxodifowoxaw.pdf
SUSPICIOUS — setimasefuxodifowoxaw.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
02436d92bc1a7598067d31b844965de2ac9d55a00f3ca46eac758692305393f7 - SHA-1:
5b760454457bf415391cc104aae08f4db4587eaa - MD5:
f8874ed07c26b3222951f3e1887e9fe3 - ssdeep:
768:agGzpDNpR3B6k/K9c5Lq3jS/6/nJKI6es4rTyffnhPQVe:HGFRpAS/7zemXhoVe - TLSH:
T142318DB34167DD8C3A869B13ADBA14685186CB4D7133EBB44488772CC47C6BDBF40A61 - Submitted as: setimasefuxodifowoxaw.pdf
- File type: pdf · Size: 40120 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=sap+warehouse+management+martin+murray+pdf, https://site-1039515.mozfiles.com/files/1039515/44878615609.pdf, https://site-1037048.mozfiles.com/files/1037048/nemeruzoledowotajitibivex.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=sap+warehouse+management+martin+murray+pdf
- https://site-1039515.mozfiles.com/files/1039515/44878615609.pdf
- https://site-1037048.mozfiles.com/files/1037048/nemeruzoledowotajitibivex.pdf
- https://site-1036951.mozfiles.com/files/1036951/detikepoveduxaxoruwo.pdf
- https://site-1038592.mozfiles.com/files/1038592/62133625617.pdf
- https://site-1039285.mozfiles.com/files/1039285/giraparalemagamexugulefin.pdf
- https://uploads.strikinglycdn.com/files/d6695353-4be4-4bcb-9b4c-7d5b3d800182/84947391238.pdf
- https://uploads.strikinglycdn.com/files/e6efe464-00b1-4589-ad32-2addc6e327ed/9999712381.pdf
- https://uploads.strikinglycdn.com/files/40e4a82b-623e-4419-a734-483938877d72/dixetediduto.pdf
- https://uploads.strikinglycdn.com/files/0499015a-af3c-48f6-adca-efc448bfff50/31308145065.pdf
- https://cdn.shopify.com/s/files/1/0440/7794/0886/files/nedatixedemifejovum.pdf
- https://cdn.shopify.com/s/files/1/0461/6444/3299/files/the_good_braider_chapter_summary.pdf
- https://cdn.shopify.com/s/files/1/0429/9423/7593/files/bafulunogisivuxelisu.pdf
- http://files.mohlerdance.net/uploads/1/3/2/6/132681657/331296d0f.pdf
- http://files.eaglesobx.org/uploads/1/3/1/6/131606540/gilananose-vujafanipukumip-perimel.pdf
- http://files.classicalprep.com/uploads/1/3/0/7/130776525/tuwukifoxeterakuna.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1039515.mozfiles.com
- site-1037048.mozfiles.com
- site-1036951.mozfiles.com
- site-1038592.mozfiles.com
- site-1039285.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- files.mohlerdance.net
- files.eaglesobx.org
- files.classicalprep.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report