SUSPICIOUS — bugajinamorolo.pdf
SUSPICIOUS — bugajinamorolo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
4607c982f1b9213e0234c5b0edb8a2ca09712b3a3feeed893f80d1716e10816c - SHA-1:
7d41ada298eef6e2d0a1be871360ee6527676fdd - MD5:
4a40f13f0b062e9cea6e8e18ebbdf335 - ssdeep:
768:5gGzpDefra3Kod8Pj/LwwPspo+a5yEYzJmbsAnRVPLZpjptmFfoxrvOS6i:6GFSjMKMA/oO+EPLZgGLOS6i - TLSH:
T17832AEF784A7EC8D7A8B8F03A9D61506544CDB886237A76009C8732CD47C2BDAF10962 - Submitted as: bugajinamorolo.pdf
- File type: pdf · Size: 44267 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=sample+acting+resume+pdf, http://files.huapaiponyclub.co.nz/uploads/1/3/2/3/132303245/meleke_ruwavideperaka.pdf, http://tenogop.21stcenturymediaplanning.com/uploads/1/3/1/4/131437889/4753ca285522be.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=sample+acting+resume+pdf
- http://files.huapaiponyclub.co.nz/uploads/1/3/2/3/132303245/meleke_ruwavideperaka.pdf
- http://tenogop.21stcenturymediaplanning.com/uploads/1/3/1/4/131437889/4753ca285522be.pdf
- http://files.alternativewildlifesolutions.com/uploads/1/3/1/6/131606059/xixuzetosur.pdf
- http://files.openheartstudio.org/uploads/1/3/1/6/131606493/pekunavatumivev.pdf
- http://wuwiv.journeyomyoga.com/uploads/1/3/1/3/131380344/jizuxanup_vojinuxobug_razojekomo.pdf
- https://cdn.shopify.com/s/files/1/0433/4567/4389/files/balsa_wood_structure_odyssey_mind.pdf
- https://cdn.shopify.com/s/files/1/0431/2399/8874/files/emerson_lc401em3f_manual.pdf
- https://cdn.shopify.com/s/files/1/0478/2882/8319/files/96241757178.pdf
- https://cdn.shopify.com/s/files/1/0479/4492/5340/files/wolebarumoxidujuxava.pdf
- https://cdn.shopify.com/s/files/1/0479/2808/2599/files/tapabenasise.pdf
- https://cdn.shopify.com/s/files/1/0481/4169/7187/files/12014060365.pdf
- https://cdn.shopify.com/s/files/1/0459/0433/0906/files/7127682402.pdf
- https://cdn.shopify.com/s/files/1/0435/8835/4211/files/posivob.pdf
- https://cdn.shopify.com/s/files/1/0485/2678/6715/files/filixisitokuvipajuful.pdf
- https://cdn.shopify.com/s/files/1/0431/8799/4792/files/ode_to_aphrodite_poem_analysis.pdf
- https://cdn.shopify.com/s/files/1/0477/5057/8332/files/butler_county_jail_pa.pdf
- https://cdn.shopify.com/s/files/1/0431/9523/6513/files/66886062943.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- tenogop.21stcenturymediaplanning.com
- files.alternativewildlifesolutions.com
- files.openheartstudio.org
- wuwiv.journeyomyoga.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
- files.huapaiponyclub.co.nz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report