SUSPICIOUS — muvimelosufowebaruvirejan.pdf
SUSPICIOUS — muvimelosufowebaruvirejan.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
033ef431a38c3828b4eb7013bddaac6994a4c7fa40c1f79eaf93d78725bb5336 - SHA-1:
694499cd7598aed0d21e30e44b1bb22b1a1b7934 - MD5:
9091694c4c8b4759706f25daa5c61ff3 - ssdeep:
768:/gGzpDBwYKzVWQD3ws0VVWG9irf4zilUCpVZ0xzMjpK40ml2S39ZsVI1d:IGF9tqMsGExdlUKZ02jpK4ntZs21d - TLSH:
T1E031AEF340A7DD4C7A87AB839DA705A1609AC3882162E75058CD3B6DD47C7BDBF409A0 - Submitted as: muvimelosufowebaruvirejan.pdf
- File type: pdf · Size: 41900 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=o+mio+babbino+caro+piano+solo+pdf, https://site-1036691.mozfiles.com/files/1036691/zigeduvojudini.pdf, https://site-1036796.mozfiles.com/files/1036796/tavabajuv.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=o+mio+babbino+caro+piano+solo+pdf
- https://site-1036691.mozfiles.com/files/1036691/zigeduvojudini.pdf
- https://site-1036796.mozfiles.com/files/1036796/tavabajuv.pdf
- https://site-1039693.mozfiles.com/files/1039693/ninefoz.pdf
- https://site-1043574.mozfiles.com/files/1043574/79079932287.pdf
- https://site-1040263.mozfiles.com/files/1040263/kezexi.pdf
- http://botixab.aperfectdayevent.com/uploads/1/3/1/3/131382439/lujogir.pdf
- http://files.bushardt.com/uploads/1/3/1/8/131856119/4286237.pdf
- http://files.markchrislermusic.com/uploads/1/3/2/7/132712093/b1c638ca.pdf
- http://files.flawlessreflectionsautodetailing.com/uploads/1/3/1/4/131409037/430701.pdf
- https://cdn.shopify.com/s/files/1/0437/7837/5829/files/big_ideas_math_geometry_student_journal_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0437/9469/4304/files/the_art_of_mackin_free.pdf
- https://cdn.shopify.com/s/files/1/0440/4844/9701/files/daganokiruzezuf.pdf
- https://uploads.strikinglycdn.com/files/733f39ac-5baf-46bb-a909-3c40b93e8b36/50324534904.pdf
- https://uploads.strikinglycdn.com/files/1e65a333-7792-4695-b32b-40505b02070b/jajunovotugadipovike.pdf
- https://uploads.strikinglycdn.com/files/7e6387a0-2d65-4228-86d1-716f59ab9ec1/werafekegujavifidag.pdf
- https://uploads.strikinglycdn.com/files/ea873648-f5a8-46b5-b00c-a6238b7fe58b/pefobazokupokovewan.pdf
- https://uploads.strikinglycdn.com/files/93850ef5-f7df-4636-a293-08eb89ff8d63/vijafowekum.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1036691.mozfiles.com
- site-1036796.mozfiles.com
- site-1039693.mozfiles.com
- site-1043574.mozfiles.com
- site-1040263.mozfiles.com
- botixab.aperfectdayevent.com
- files.bushardt.com
- files.markchrislermusic.com
- files.flawlessreflectionsautodetailing.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report