SUSPICIOUS — rutiziz_muzub_gawek_vumolumapelot.pdf
SUSPICIOUS — rutiziz_muzub_gawek_vumolumapelot.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
4ed9d50826d677d152dd5ffa7ceae3012afca67f5fa642156d64a1c543bfcb60 - SHA-1:
7c690b763fc9939e6d18c8438c3a32d8ef107562 - MD5:
320564f03bd79cc280f8299b73796601 - ssdeep:
768:+gGzpDMpqWR3UiY3j2q8nAHNFrx0PtaE/Ouk1mh2Pj4/W88AJRINCv7h7sIa/9ik:7GFQpqcjb6YhGjYT8IIEv72IarXG8AZc - TLSH:
T11E328DF364D7ED4C7A879B03ADE72069688DC7482236A750089C772CD4BC6ADBF10960 - Submitted as: rutiziz_muzub_gawek_vumolumapelot.pdf
- File type: pdf · Size: 47123 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=weber%20carburetor%20book%20pdf, https://uploads.strikinglycdn.com/files/c7de0547-e14d-428d-bd4d-dea3dd7c54af/kamofomufexukob.pdf, https://uploads.strikinglycdn.com/files/48102750-1fb1-4a67-b173-430186f4d644/4065065842.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=weber%20carburetor%20book%20pdf
- https://uploads.strikinglycdn.com/files/c7de0547-e14d-428d-bd4d-dea3dd7c54af/kamofomufexukob.pdf
- https://uploads.strikinglycdn.com/files/48102750-1fb1-4a67-b173-430186f4d644/4065065842.pdf
- https://uploads.strikinglycdn.com/files/b3bdfd02-e023-4625-8a8d-3b2f85ffd5a6/kogak.pdf
- https://uploads.strikinglycdn.com/files/7ab181f5-3034-4dba-93c5-74763f6f5213/39161509211.pdf
- https://uploads.strikinglycdn.com/files/a4242030-423a-4c2c-9992-80eb9f789176/dilegajamigawukujedika.pdf
- https://uploads.strikinglycdn.com/files/ce5b7549-3653-4e9b-8843-627ce8392ee3/81385634459.pdf
- https://uploads.strikinglycdn.com/files/4bbb020d-6863-4ba1-ae88-0eba1ca25725/lawasezu.pdf
- https://uploads.strikinglycdn.com/files/65d0fadd-7c1b-4433-b405-8489167b1f1f/77741925741.pdf
- https://uploads.strikinglycdn.com/files/3d85f121-a826-4ff9-b34a-a95630d25d46/26008512423.pdf
- https://cdn-cms.f-static.net/uploads/4366034/normal_5f8a09eff3eb6.pdf
- https://cdn-cms.f-static.net/uploads/4368781/normal_5f87e09c6354d.pdf
- https://cdn-cms.f-static.net/uploads/4375703/normal_5f8a1483379c8.pdf
- https://cdn.shopify.com/s/files/1/0429/0949/9558/files/spotify_premium_offline_mod_apk_2020.pdf
- https://cdn.shopify.com/s/files/1/0433/4052/9816/files/overloading_vs_overriding_in_oop.pdf
- https://cdn.shopify.com/s/files/1/0431/3628/6877/files/strong_and_weak_acids_and_bases_mcat.pdf
- https://cdn.shopify.com/s/files/1/0432/5431/7214/files/2809576915.pdf
- https://cdn.shopify.com/s/files/1/0483/8250/9216/files/baxokaminupujit.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f8946a493fe8.pdf
- https://cdn-cms.f-static.net/uploads/4367667/normal_5f876895a270f.pdf
- https://cdn-cms.f-static.net/uploads/4377403/normal_5f8a0f1707ac3.pdf
- https://cdn-cms.f-static.net/uploads/4366347/normal_5f87eb242761b.pdf
- https://cdn-cms.f-static.net/uploads/4366676/normal_5f872fc74c42f.pdf
- https://cdn.shopify.com/s/files/1/0484/5361/5770/files/47714480288.pdf
- https://cdn.shopify.com/s/files/1/0433/6615/4394/files/bimexuji.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- n.io
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report