SUSPICIOUS — cessar_ou_site_http_enccejanaciona.pdf
SUSPICIOUS — cessar_ou_site_http_enccejanaciona.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
392c035e02c21b281ccbe069f684fdb700afa453a2f000315e7929ea65e8319f - SHA-1:
36e37881852cd5e93b7cd870f9500f289ba86243 - MD5:
9feb35f99bd37984496ea6ff9a0989f9 - ssdeep:
1536:kGFIpyVIomSOazLB0eDS9KSSzzbLjT5MUk2gYrmMm0:xFIpdvSBzL6m7S6zWU/gYrmK - TLSH:
T18534BEF7107BEE4D3B4B2F839EA70559658A978C703697A054887B2C84BC6EC2F00956 - Submitted as: cessar_ou_site_http_enccejanaciona.pdf
- File type: pdf · Size: 54794 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=cessar+ou+site+http+%252F%252Fenccejanaciona, https://cdn-cms.f-static.net/uploads/4366004/normal_5f8702eb03638.pdf, https://cdn-cms.f-static.net/uploads/4365613/normal_5f871d50e0349.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=cessar+ou+site+http+%252F%252Fenccejanaciona
- https://cdn-cms.f-static.net/uploads/4366004/normal_5f8702eb03638.pdf
- https://cdn-cms.f-static.net/uploads/4365613/normal_5f871d50e0349.pdf
- https://cdn-cms.f-static.net/uploads/4366011/normal_5f87106d9181e.pdf
- https://cdn-cms.f-static.net/uploads/4369766/normal_5f8827461dafc.pdf
- https://cdn-cms.f-static.net/uploads/4373998/normal_5f8a1a34782a8.pdf
- https://cdn-cms.f-static.net/uploads/4366376/normal_5f8739d5b3934.pdf
- https://vidojibirulon.weebly.com/uploads/1/3/1/0/131070792/vigebonidonuju-puwabawu-ranepobexewo.pdf
- https://rabifupokuwu.weebly.com/uploads/1/3/1/1/131164250/8444efb68af.pdf
- https://uploads.strikinglycdn.com/files/00b34518-b26f-4b37-bd05-287dd3279ec5/kavotege.pdf
- https://uploads.strikinglycdn.com/files/ea880539-b1ac-46b6-94ca-69484f13e93b/11037479523.pdf
- https://uploads.strikinglycdn.com/files/e7d41f72-f663-48ec-8ddf-dac3c244eb46/tepoziwo.pdf
- https://uploads.strikinglycdn.com/files/959d0a7f-dd35-4d8e-a144-441b4f0a6ad0/272237319.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/mikukinib.pdf
- https://jezaxegare.weebly.com/uploads/1/3/1/3/131380636/5ad64ac63a7.pdf
- https://fidegobopoj.weebly.com/uploads/1/3/2/8/132815019/naseruwuwebobezasek.pdf
- https://jumuwubugunitus.weebly.com/uploads/1/3/1/0/131070493/semagewe.pdf
- https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/gamigakusujusul.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- vidojibirulon.weebly.com
- rabifupokuwu.weebly.com
- uploads.strikinglycdn.com
- keniwuki.weebly.com
- jezaxegare.weebly.com
- fidegobopoj.weebly.com
- jumuwubugunitus.weebly.com
- kabudededawizo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report