SUSPICIOUS — pizusowexupaxom.pdf
SUSPICIOUS — pizusowexupaxom.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
4ee61c4a0b4d2f62a4db904ced37964860a1e46a0c728606bf63778cd3d5b813 - SHA-1:
604c41ea594e25f203bc4c75bc3e5d492eb3ad22 - MD5:
9851672bf318f910142f8de539a17e31 - ssdeep:
768:qIgGzpDyocRKKbGqL2ehfzapjGfBB3O5Grww8xFnqnZZ28VyDeLAqupp1h:qFGFOBRzbyIy2ww0YnZZFQkcpp1h - TLSH:
T12F32AFF7508BEC8C6A4B6B47AAF60159715BD6CD3036E36419C87B2CC0787BC6E10A61 - Submitted as: pizusowexupaxom.pdf
- File type: pdf · Size: 46041 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=pioneer+rt-707+user+manual, https://uploads.strikinglycdn.com/files/fa465d07-485b-4a3d-a2b3-2dfa05313531/revetofegezapamako.pdf, https://uploads.strikinglycdn.com/files/7f7c44bb-99fd-411a-ad9b-ce922230e0df/bagaxesivogaligulizolog.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=pioneer+rt-707+user+manual
- https://uploads.strikinglycdn.com/files/fa465d07-485b-4a3d-a2b3-2dfa05313531/revetofegezapamako.pdf
- https://uploads.strikinglycdn.com/files/7f7c44bb-99fd-411a-ad9b-ce922230e0df/bagaxesivogaligulizolog.pdf
- https://uploads.strikinglycdn.com/files/843ee4d1-fd4f-4a52-9263-783a2b35a342/rozurukanotujupewajol.pdf
- https://uploads.strikinglycdn.com/files/6e9384f3-740f-4a63-b718-a3acdd55cdb1/kudojosa.pdf
- https://uploads.strikinglycdn.com/files/708cbfea-d65c-4a74-9dd1-e5c23bb3bc34/lufowawibijezefabi.pdf
- http://files.wickedricks.com/uploads/1/3/1/4/131454620/9c578dd0c9d5.pdf
- http://files.overcomeporn.org/uploads/1/3/2/6/132695535/2512462.pdf
- https://cdn.shopify.com/s/files/1/0428/4776/4636/files/the_young_indiana_jones_chronicles_where_to_watch.pdf
- https://cdn.shopify.com/s/files/1/0433/0743/4142/files/busubov.pdf
- https://cdn.shopify.com/s/files/1/0434/5603/7017/files/jawufoxasosurupavinewazuj.pdf
- https://cdn.shopify.com/s/files/1/0484/4965/0838/files/manual_recaro_monza.pdf
- https://uploads.strikinglycdn.com/files/974d7b1e-62bb-455c-8215-58cf0d1f2084/bowufogavukubowagipazidep.pdf
- https://uploads.strikinglycdn.com/files/90df985d-28cd-480d-8b6f-b55345594f9d/64317019152.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- files.wickedricks.com
- files.overcomeporn.org
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report