SUSPICIOUS — bevutarelerusoxuros.pdf
SUSPICIOUS — bevutarelerusoxuros.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
0e7867b80ebe6f06d947b3cca1b1e099159e4fac8beaea65aae9beb4aab4e175 - SHA-1:
509209ebbca59078a8a55613b33ab19e1edaad6a - MD5:
5d9a74d00eb5a4a97bd367be3f335e7c - ssdeep:
768:xgGzpDfUrtz8xgKagjUJ/cjdAHAWRd5++THGNawtPVRC8Xr8GToGFE8n6QsvElHy:CGFbMg40jeHAWRd5mNa6jCaFoGW8XsvZ - TLSH:
T1F2329EF350A3ED8C6E8A7F135D96056AA186C2CD2036A76009DC776CC47C7FD9E10AA1 - Submitted as: bevutarelerusoxuros.pdf
- File type: pdf · Size: 45569 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=battletech+bull+shark, https://uploads.strikinglycdn.com/files/ae14331e-aa28-47b6-ad40-ea4936666a7f/tuvizefajokatatu.pdf, https://uploads.strikinglycdn.com/files/6d50f0c1-8d61-476e-bab2-841938ac5845/renazoxisizebemitojur.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=battletech+bull+shark
- https://uploads.strikinglycdn.com/files/ae14331e-aa28-47b6-ad40-ea4936666a7f/tuvizefajokatatu.pdf
- https://uploads.strikinglycdn.com/files/6d50f0c1-8d61-476e-bab2-841938ac5845/renazoxisizebemitojur.pdf
- https://uploads.strikinglycdn.com/files/2e1f428e-7b61-48a1-a123-cb7ebf1aa206/nufelerozakorelove.pdf
- https://uploads.strikinglycdn.com/files/1abca47b-3066-434f-b3f8-3610846e47d1/66962763234.pdf
- https://uploads.strikinglycdn.com/files/8f88e7ef-7bd0-4f75-ade8-425ad6f4c656/nupatadadufimake.pdf
- https://cdn.shopify.com/s/files/1/0437/5468/4565/files/zubimewaveluto.pdf
- https://cdn.shopify.com/s/files/1/0457/6110/1980/files/analytical_interview_questions_for_programmers.pdf
- https://cdn.shopify.com/s/files/1/0431/5496/4637/files/maguvuvotubukupojezewelu.pdf
- https://cdn.shopify.com/s/files/1/0432/8721/6293/files/xedaxob.pdf
- https://cdn.shopify.com/s/files/1/0430/6694/9799/files/43481836335.pdf
- https://uploads.strikinglycdn.com/files/d0a466be-005a-4045-b368-d72c5e028a0c/leronifiratik.pdf
- https://uploads.strikinglycdn.com/files/8290fc1a-ea7c-4d78-b08b-c31c21505967/91575288617.pdf
- http://files.thecapacitygroup.org/uploads/1/3/1/3/131380163/e8c439ff.pdf
- http://dadasezim.nowwwriters.ca/uploads/1/3/1/1/131164278/8531942.pdf
- http://files.cpprocketry.net/uploads/1/3/2/6/132695384/38e6381630bb15.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- files.thecapacitygroup.org
- dadasezim.nowwwriters.ca
- files.cpprocketry.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report