SUSPICIOUS — neputizel.pdf
SUSPICIOUS — neputizel.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
376b0f1d0a8ae47d2159e6fd418a38c56318d62c9603a99f6ccbea3157c7a7b4 - SHA-1:
71f46dc03883fa876591777530de1ff43261b968 - MD5:
a243f4b7829ae3fefb5051afdd1010d1 - ssdeep:
1536:HGFVpNqvF7Zeb6aYAUYsOJUi1zWlyg1KHpq5:mFVp8vXe+a3sw165cHW - TLSH:
T1C835CFF35067ED8C76C79B03B9E6201A6148CB486173A76449CC7B2DD57C2FEAE109A0 - Submitted as: neputizel.pdf
- File type: pdf · Size: 60714 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=singing+machine+karaoke+user+manual, https://cdn.shopify.com/s/files/1/0484/2674/6024/files/96020610753.pdf, https://cdn.shopify.com/s/files/1/0431/9599/0175/files/goruvukorareruw.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=singing+machine+karaoke+user+manual
- https://cdn.shopify.com/s/files/1/0484/2674/6024/files/96020610753.pdf
- https://cdn.shopify.com/s/files/1/0431/9599/0175/files/goruvukorareruw.pdf
- https://cdn.shopify.com/s/files/1/0496/1370/1283/files/step_2_picnic_table_walmart.pdf
- https://cdn.shopify.com/s/files/1/0434/4227/4471/files/1981_topps_baseball_cards_price_guide.pdf
- https://site-1043199.mozfiles.com/files/1043199/devilbiss_suction_machine_7305p-d_manual.pdf
- https://site-1038925.mozfiles.com/files/1038925/wafuko.pdf
- https://cdn.shopify.com/s/files/1/0428/6378/8188/files/78790935687.pdf
- https://cdn.shopify.com/s/files/1/0434/1887/8104/files/gupetusadadipuwisediku.pdf
- https://cdn.shopify.com/s/files/1/0436/5864/1561/files/mary_ruth_organics_zinc.pdf
- https://cdn.shopify.com/s/files/1/0431/5083/5878/files/savutizuniwefolixetupek.pdf
- https://cdn-cms.f-static.net/uploads/4368999/normal_5f88ce643f0cc.pdf
- https://cdn-cms.f-static.net/uploads/4366982/normal_5f872bcbe573c.pdf
- https://cdn.shopify.com/s/files/1/0431/0394/4853/files/airtel_international_roaming_sms.pdf
- https://cdn.shopify.com/s/files/1/0433/0287/9387/files/stainless_steel_rivets_lowes.pdf
- https://cdn.shopify.com/s/files/1/0432/2269/6098/files/nawimilebemopefepare.pdf
- https://cdn.shopify.com/s/files/1/0439/2094/9403/files/ma-pi_2_diet_meal_plan.pdf
- https://site-1037848.mozfiles.com/files/1037848/gevazalamonijevureligore.pdf
- https://site-1044024.mozfiles.com/files/1044024/43007819310.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- site-1043199.mozfiles.com
- site-1038925.mozfiles.com
- cdn-cms.f-static.net
- site-1037848.mozfiles.com
- site-1044024.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report