SUSPICIOUS — mejiwuwopaxuwesevagunuw.pdf
SUSPICIOUS — mejiwuwopaxuwesevagunuw.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
52b8a5ef57a6f16449d867947b50c78819485f0605add8d4331a5f1fb11bc547 - SHA-1:
c58e54a259c584dbd5b2a6ddcd0931a99458e9da - MD5:
c3c1978874684c69ef7c354f05d4400f - ssdeep:
768:+DgGzpDGaE/ECgglmG1GNWqsPfcU8V0AZCzk1XeqKmdB:/GFiQCGNWb4ZCziXeqKmdB - TLSH:
T16732BFF70027EE8C6A876F832FE3059A6008E6893032676449587B7CC8BC5ED5F55E61 - Submitted as: mejiwuwopaxuwesevagunuw.pdf
- File type: pdf · Size: 45546 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=%25C4%2587wiczenia+na+wszystkie+czasy+angielski+pdf, https://cdn.shopify.com/s/files/1/0436/1653/4690/files/man_alpha_propulsion.pdf, https://cdn.shopify.com/s/files/1/0436/5749/4693/files/35934357763.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=%25C4%2587wiczenia+na+wszystkie+czasy+angielski+pdf
- https://cdn.shopify.com/s/files/1/0436/1653/4690/files/man_alpha_propulsion.pdf
- https://cdn.shopify.com/s/files/1/0436/5749/4693/files/35934357763.pdf
- https://cdn.shopify.com/s/files/1/0436/0460/7139/files/90727473700.pdf
- https://cdn.shopify.com/s/files/1/0481/5460/7777/files/bowflex_blaze_home_gym.pdf
- http://files.westtechmobile.com/uploads/1/3/1/4/131409158/55e6d35e896ccaf.pdf
- http://files.fearlesscounselingservices.com/uploads/1/3/2/6/132682327/papinevozaxegix-fizuvijine.pdf
- http://files.wildwiscwinterweb.com/uploads/1/3/2/6/132695388/387be4353f3495.pdf
- https://uploads.strikinglycdn.com/files/8c223c72-4136-48c9-a40e-b0ebc10683d4/xunolejetivetinizuxegem.pdf
- https://uploads.strikinglycdn.com/files/af4a4c9b-ecc0-41f3-8c02-ee6c8aec43f5/31279877173.pdf
- https://uploads.strikinglycdn.com/files/faedc704-097a-4697-a1f3-29f3be70d0e4/22777574554.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- files.westtechmobile.com
- files.fearlesscounselingservices.com
- files.wildwiscwinterweb.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report