SUSPICIOUS — diponiwuropo.pdf
SUSPICIOUS — diponiwuropo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
61719abab22f861f9265fcd144b5e5170f8b5a2b36357c8f7a5113d48882e5e5 - SHA-1:
dc4d3eb3addeee0cfbc7d16dfe6bac9032479606 - MD5:
1044e6ebc4f87145c3d9b082960b7164 - ssdeep:
1536:7GFxgbP+FFTjVc4Zh00OhfucpiGTA3/rH/ESJ3YAy:aFxdpcAhQVyZPrH/ESJ3m - TLSH:
T14D35D0F31166CDEC6AC2AB0B5DB72018119A86CD613387F455C8BABCD8BC1FC6D51922 - Submitted as: diponiwuropo.pdf
- File type: pdf · Size: 61586 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=practical+medical+entomology+pdf, http://files.faubertminiatureschnauzers.com/uploads/1/3/1/4/131437402/3188250.pdf, http://teradu.kelseyviola.com/uploads/1/3/1/3/131382028/latuso_fipakasabapofed_jizuxo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=practical+medical+entomology+pdf
- http://files.faubertminiatureschnauzers.com/uploads/1/3/1/4/131437402/3188250.pdf
- http://teradu.kelseyviola.com/uploads/1/3/1/3/131382028/latuso_fipakasabapofed_jizuxo.pdf
- http://files.barelyreality.com/uploads/1/3/0/7/130739029/b50363f321e.pdf
- http://files.soulflowerhealing.com/uploads/1/3/0/7/130775215/tadapamas-sezavageniliji-barolenolam-lefiwev.pdf
- http://files.mayamoralesofficial.com/uploads/1/3/0/9/130969371/gifijuvoti.pdf
- https://site-1044113.mozfiles.com/files/1044113/rofabuxadepikipeporoz.pdf
- https://site-1036880.mozfiles.com/files/1036880/ludujakisixamod.pdf
- http://vovig.abundanceworldwide.org/uploads/1/3/0/7/130738629/9453247.pdf
- http://fefakibon.labelletraining.com/uploads/1/3/1/1/131164250/2994495.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- files.faubertminiatureschnauzers.com
- teradu.kelseyviola.com
- files.barelyreality.com
- files.soulflowerhealing.com
- files.mayamoralesofficial.com
- site-1044113.mozfiles.com
- site-1036880.mozfiles.com
- vovig.abundanceworldwide.org
- fefakibon.labelletraining.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report