SUSPICIOUS — puwozopikeje.pdf
SUSPICIOUS — puwozopikeje.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
2014651b1b0f4256d97e50999a9a5cd7a7f2e91d0fdcefcf53850604ca92a7c8 - SHA-1:
bcc774bce9e8f77fc87257796f6cf115f6083d42 - MD5:
cbf47b62eb537e610f8576b8b5f928cf - ssdeep:
384:ZsFlS3K6XgKV7cAgdOpW+0pSsarV9qitMPM2ejvhy+bwFTMnILNX2WrtJdqlCUSQ:NgGzpDySsa2itMlMMnVsAkPMBpPmbn3 - TLSH:
T163309EF350A7EC8C7AD7AB436EB61449604AD78D603296B004DC772EC8BC6FD6E10961 - Submitted as: puwozopikeje.pdf
- File type: pdf · Size: 36444 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://traffking.ru/wb?keyword=youtube%20dantdm%20riddle%20school%20transfer%202, https://uploads.strikinglycdn.com/files/dbe0b3fb-bd91-4b47-8d32-f6f493e51c77/74396521769.pdf, https://uploads.strikinglycdn.com/files/dcc1502a-f4d4-4bcf-a0b3-4c8c4333ac24/95995445852.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffking.ru/wb?keyword=youtube%20dantdm%20riddle%20school%20transfer%202
- https://s3.amazonaws.com/kitakilesa/ruvizuxim.pdf
- https://uploads.strikinglycdn.com/files/dbe0b3fb-bd91-4b47-8d32-f6f493e51c77/74396521769.pdf
- https://uploads.strikinglycdn.com/files/dcc1502a-f4d4-4bcf-a0b3-4c8c4333ac24/95995445852.pdf
- https://uploads.strikinglycdn.com/files/0ea5c548-898b-4686-971a-202fe1b011d6/81797001495.pdf
- https://uploads.strikinglycdn.com/files/af24e4fb-3337-4af7-8239-41fd1b7c3808/bevavipoxovijip.pdf
- https://uploads.strikinglycdn.com/files/1f3e5e36-0bc3-4f93-bcbc-dbd53cab7574/zamogudimuz.pdf
- https://ditiwudo.weebly.com/uploads/1/3/1/4/131452947/8456019.pdf
- https://uploads.strikinglycdn.com/files/21456f71-b50f-43e9-91b0-3104d815985a/ninokelem.pdf
- https://pafudufuwod.weebly.com/uploads/1/3/4/3/134326080/241745.pdf
- https://s3.amazonaws.com/muvunekagok/28427816805.pdf
- https://saxexowiki.weebly.com/uploads/1/3/0/9/130969873/44b2c6c.pdf
- https://uploads.strikinglycdn.com/files/de5b8ee1-2fa5-49ba-8299-85aad170a60c/32141705191.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffking.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- ditiwudo.weebly.com
- pafudufuwod.weebly.com
- saxexowiki.weebly.com
- riddleschoolgame.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report