SUSPICIOUS — ranusadufej.pdf
SUSPICIOUS — ranusadufej.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
4ebfcc5c8af3f674775bac99965baaa0460247f37c930ea58a586d3a9148160a - SHA-1:
34675544b40cff1620248b278f9d2707ec9421ea - MD5:
40a71e8cad8e795a3d746d01fc7a2c4f - ssdeep:
768:QcgGzpDVponcr5Tak7SKYQ7zgUyRzb9OCx/br2UtcInMIktJpJsF/QeCVCH:UGFZpr5SH/3BnMIkt/6dyVCH - TLSH:
T143348EF360A7DD4D36CAAB036DEB24299149D74C62729760849C773CC4BC2BE2E11A91 - Submitted as: ranusadufej.pdf
- File type: pdf · Size: 52343 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=download+epsxe+apk+++bios+android, https://cdn.shopify.com/s/files/1/0496/3690/1013/files/door_hinge_template_for_router.pdf, https://cdn.shopify.com/s/files/1/0500/4053/7277/files/davawanetemakira.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=download+epsxe+apk+++bios+android
- https://cdn.shopify.com/s/files/1/0496/3690/1013/files/door_hinge_template_for_router.pdf
- https://cdn.shopify.com/s/files/1/0500/4053/7277/files/davawanetemakira.pdf
- https://cdn.shopify.com/s/files/1/0437/1048/0533/files/bizotitodaj.pdf
- https://cdn.shopify.com/s/files/1/0502/8898/4222/files/jerevaviruvezivi.pdf
- https://bubixoduxufito.weebly.com/uploads/1/3/1/0/131070588/8476882.pdf
- https://cdn-cms.f-static.net/uploads/4377679/normal_5f8ef156ed164.pdf
- https://cdn-cms.f-static.net/uploads/4370542/normal_5f88b2bf35bd1.pdf
- https://cdn-cms.f-static.net/uploads/4374984/normal_5f8e5cc2e03d6.pdf
- https://cdn.shopify.com/s/files/1/0482/8433/6283/files/get_to_know_me_tag_youtube.pdf
- https://cdn.shopify.com/s/files/1/0501/0279/6442/files/bafege.pdf
- https://cdn.shopify.com/s/files/1/0497/5008/1690/files/present_simple_negative_form_worksheet.pdf
- https://jiwepurojal.weebly.com/uploads/1/3/0/7/130775762/2824351.pdf
- https://naxesitigas.weebly.com/uploads/1/3/0/7/130740165/mizopalogutixe-fotokikuzoga.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/36ce75ac.pdf
- https://gozofuma.weebly.com/uploads/1/3/0/8/130874065/mezegaliza-mimet-gukilomodekaje-vaxibopekexiti.pdf
- https://pudukodup.weebly.com/uploads/1/3/1/4/131407572/bazezopid_lokukojakuzi.pdf
- https://zevigetadafuwun.weebly.com/uploads/1/3/0/9/130969942/galebigajetij.pdf
- https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/jamapuz.pdf
- https://riragojefo.weebly.com/uploads/1/3/1/8/131857115/naxurupeg.pdf
- https://rugurujumififez.weebly.com/uploads/1/3/1/3/131384765/7348be00b09a91.pdf
- https://xuwuperozaposa.weebly.com/uploads/1/3/2/3/132303395/tikowofibimerozinozu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- bubixoduxufito.weebly.com
- cdn-cms.f-static.net
- jiwepurojal.weebly.com
- naxesitigas.weebly.com
- dutitujazekap.weebly.com
- gozofuma.weebly.com
- pudukodup.weebly.com
- zevigetadafuwun.weebly.com
- tivakoxidedopa.weebly.com
- riragojefo.weebly.com
- rugurujumififez.weebly.com
- xuwuperozaposa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report