SUSPICIOUS — riwesadixotorewu.pdf
SUSPICIOUS — riwesadixotorewu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
5b5c5816fcc31e6a412e47ea3089bcf07fd21071688f3abc656b5d9d589f592b - SHA-1:
d23f4ff646ea11ecd6991b9e6da4f7e180361322 - MD5:
579401cf136ca9e9ab737cc1c95a528d - ssdeep:
768:vgGzpDFp4vp7lF5wKaCEmEV+OVBHeuxPCrLUxVIeVMdjBsdocINj+VypSf+:YGFJp4xeKaC/LCPCrLcIeVMdFUocG2yj - TLSH:
T1CD328DF75067ED8C7B879B036EE6114DA046D78921329BA4488C7B7CC47C2FD6E40A61 - Submitted as: riwesadixotorewu.pdf
- File type: pdf · Size: 44749 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=dometic+3+way+fridge+freezer+manual, https://site-1040165.mozfiles.com/files/1040165/20326148474.pdf, https://site-1036742.mozfiles.com/files/1036742/11965848676.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=dometic+3+way+fridge+freezer+manual
- https://site-1040165.mozfiles.com/files/1040165/20326148474.pdf
- https://site-1036742.mozfiles.com/files/1036742/11965848676.pdf
- https://site-1039795.mozfiles.com/files/1039795/7110280905.pdf
- https://cdn.shopify.com/s/files/1/0498/4599/3634/files/raxojeb.pdf
- https://cdn.shopify.com/s/files/1/0431/3228/9178/files/greene_county_arkansas.pdf
- https://cdn.shopify.com/s/files/1/0429/7300/3939/files/hill_climb_racing_2_mod_apk_download_apkpure.pdf
- https://cdn.shopify.com/s/files/1/0459/2061/6599/files/revumubawet.pdf
- https://cdn.shopify.com/s/files/1/0501/7426/3456/files/63868928799.pdf
- http://files.nathanbohach.com/uploads/1/3/2/7/132741615/magonufapuzote_jevuvuw.pdf
- http://pitamu.nickjagger.org/uploads/1/3/0/8/130814339/pizaporezagiwofuxeko.pdf
- http://files.ricoricarecords.com/uploads/1/3/1/4/131453010/5bf7b58334f6fb.pdf
- https://site-1036652.mozfiles.com/files/1036652/59487942041.pdf
- https://site-1036950.mozfiles.com/files/1036950/7763087544.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1040165.mozfiles.com
- site-1036742.mozfiles.com
- site-1039795.mozfiles.com
- cdn.shopify.com
- files.nathanbohach.com
- pitamu.nickjagger.org
- files.ricoricarecords.com
- site-1036652.mozfiles.com
- site-1036950.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report