SUSPICIOUS — rutabojoridole.pdf
SUSPICIOUS — rutabojoridole.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
19fbd785d847d29f6e922a156f90395caf9abfebce4cd47afdf54827c0f0dc34 - SHA-1:
36f631a1c9eceaa9476e9968000af87b8a972547 - MD5:
f4658e951f3ac433ca5b5ac39b7d67cf - ssdeep:
768:0JgGzpDBpKzF5ctUwgHP5RcNrXzjIZF6Z3ca0Y:ZGFVpWcAHXcNryF6Zsa0Y - TLSH:
T165307CF354A7DD8D7EC79B836DBA2159214AC3C87227A3604598A72DC4BC6BD3F10860 - Submitted as: rutabojoridole.pdf
- File type: pdf · Size: 36437 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=epidemiolog%25C3%25ADa+cl%25C3%25ADnica+laura+moreno+altamirano+pdf, http://files.projetmandrillus.com/uploads/1/3/2/6/132681504/2288686.pdf, http://files.bizsign.shop/uploads/1/3/1/1/131164281/b037d5b53b8d55.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=epidemiolog%25C3%25ADa+cl%25C3%25ADnica+laura+moreno+altamirano+pdf
- http://files.projetmandrillus.com/uploads/1/3/2/6/132681504/2288686.pdf
- http://files.bizsign.shop/uploads/1/3/1/1/131164281/b037d5b53b8d55.pdf
- http://files.lumbercityfarmday.org/uploads/1/3/1/0/131070612/8826fc13cbca717.pdf
- http://minixoj.sevdasfitnesstherapy.com/uploads/1/3/1/3/131378950/6e8097cf4f0685.pdf
- http://files.acc-hsg.org/uploads/1/3/0/7/130775309/4802783.pdf
- https://uploads.strikinglycdn.com/files/3baa771b-ceaa-4596-80ee-8e3abe24c5b8/4985200568.pdf
- https://uploads.strikinglycdn.com/files/aadef0cf-045b-47c3-b90b-6082b0e262a6/72032581466.pdf
- https://uploads.strikinglycdn.com/files/98c235a3-5100-4152-957c-a3df6ca0f102/timerodagujeze.pdf
- https://uploads.strikinglycdn.com/files/3b63a4ab-a2b0-47e2-981a-d80b0bccf81d/10032417411.pdf
- https://site-1037828.mozfiles.com/files/1037828/makegare.pdf
- https://site-1036627.mozfiles.com/files/1036627/dipolatodakisewelofinaje.pdf
- https://site-1041944.mozfiles.com/files/1041944/73066964266.pdf
- https://site-1038952.mozfiles.com/files/1038952/zitodosim.pdf
- https://uploads.strikinglycdn.com/files/96ec5f90-08a2-4b43-9a9a-f979f7d0c2f4/laminapefobadivog.pdf
- https://uploads.strikinglycdn.com/files/006b239c-f16e-42dd-b85a-c40ed8efabd7/walibinafebobaserilil.pdf
- https://uploads.strikinglycdn.com/files/3079a960-a865-4d76-bacf-13bf6100d2b0/74568084582.pdf
- https://uploads.strikinglycdn.com/files/57479bac-1669-44dc-9eb4-ebb3618ef688/86545743934.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- files.projetmandrillus.com
- files.bizsign.shop
- files.lumbercityfarmday.org
- minixoj.sevdasfitnesstherapy.com
- files.acc-hsg.org
- uploads.strikinglycdn.com
- site-1037828.mozfiles.com
- site-1036627.mozfiles.com
- site-1041944.mozfiles.com
- site-1038952.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report