SUSPICIOUS — nokupadanudolefirupas.pdf
SUSPICIOUS — nokupadanudolefirupas.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
0be0ca08dae728e2127e4bb6d64b72498da4884188195ed037ece1ef68081c0e - SHA-1:
66286a1ec160581fe3d8c0c8b21bad53cdd61573 - MD5:
f37d12fcd5a64e0bacf4ccb45dc2f160 - ssdeep:
768:5gGzpDeL2O+PPy/+Pu3pvSUjcWF3GSxiSxcnqVCZ9B3NptzAJgcvD:6GFaLMDuhIWF3flCnqYZ9B3Np/cvD - TLSH:
T1B333CFF751A7FD8C7ACF674368A744586091C788622393A009D87B7C84BC3EDAF11A21 - Submitted as: nokupadanudolefirupas.pdf
- File type: pdf · Size: 51692 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=winter+feeding+bees+dry+sugar, http://files.maggieessig.com/uploads/1/3/2/3/132303238/921324.pdf, http://files.calebeverett.org/uploads/1/3/1/4/131483249/fba34780.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=winter+feeding+bees+dry+sugar
- http://files.maggieessig.com/uploads/1/3/2/3/132303238/921324.pdf
- http://files.calebeverett.org/uploads/1/3/1/4/131483249/fba34780.pdf
- http://rumun.privatecounsellingandmediation.com/uploads/1/3/0/7/130775565/6f575.pdf
- http://files.roosiphoto.com/uploads/1/3/1/1/131163535/4321903.pdf
- http://files.drewgentle.com/uploads/1/3/0/7/130775484/ee349e7713b3.pdf
- http://files.sanchithaeventmanagement.com/uploads/1/3/0/8/130874244/24652efd2.pdf
- https://site-1042539.mozfiles.com/files/1042539/62200105494.pdf
- https://site-1036629.mozfiles.com/files/1036629/favexofiboxako.pdf
- https://site-1042780.mozfiles.com/files/1042780/20578457541.pdf
- https://site-1040869.mozfiles.com/files/1040869/robomuman.pdf
- http://files.repllc.net/uploads/1/3/2/3/132302857/wapej_jeborubijid_piditewejekuli.pdf
- http://files.ecosphererestorationinstitute.org/uploads/1/3/1/4/131437276/2764188.pdf
- http://gojuwez.smokymountaink9sports.com/uploads/1/3/0/7/130775795/ruzabuxud.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- files.maggieessig.com
- files.calebeverett.org
- rumun.privatecounsellingandmediation.com
- files.roosiphoto.com
- files.drewgentle.com
- files.sanchithaeventmanagement.com
- site-1042539.mozfiles.com
- site-1036629.mozfiles.com
- site-1042780.mozfiles.com
- site-1040869.mozfiles.com
- files.repllc.net
- files.ecosphererestorationinstitute.org
- gojuwez.smokymountaink9sports.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report