SUSPICIOUS — the_tire_store_wichita_ks.pdf
SUSPICIOUS — the_tire_store_wichita_ks.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
6b2d5d65e2d03cb7b781343b4607d8a42dc3718f370eafeefd15b97094cd6b8d - SHA-1:
caf975af8db35b1abed7911494fa10f4636d3057 - MD5:
aded7ad918b972ae4a729e7a890526a4 - ssdeep:
768:lgGzpDipIpf151n24qiEXbnsZoyZFH4PWI9rMENNm26rJ2EZ0W8BzY//HuZ:2GFupE1MvTioyT4PWI94E7mF3Z0WuY/Q - TLSH:
T1B2327DF340A7DDCC7ACB9B43ADAB214D654BD788702796A05488376CC4BC6BE6F00961 - Submitted as: the_tire_store_wichita_ks.pdf
- File type: pdf · Size: 46047 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=the+tire+store+wichita+ks, https://viwuwobigoku.weebly.com/uploads/1/3/1/3/131378942/rususosotetemut_tuvafirojono_vabawuvaxoxupe_lakonedimuno.pdf, https://rirumuzog.weebly.com/uploads/1/3/4/1/134109041/wakab-tutovusuboke-lidagenali.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=the+tire+store+wichita+ks
- https://viwuwobigoku.weebly.com/uploads/1/3/1/3/131378942/rususosotetemut_tuvafirojono_vabawuvaxoxupe_lakonedimuno.pdf
- https://rirumuzog.weebly.com/uploads/1/3/4/1/134109041/wakab-tutovusuboke-lidagenali.pdf
- https://jamafijuzu.weebly.com/uploads/1/3/1/4/131437216/4633433.pdf
- https://tovozilulu.weebly.com/uploads/1/3/0/8/130873983/fenikezekovabor_pobapisiseli_majunokitelufe_buremejibet.pdf
- https://tenikekiso.weebly.com/uploads/1/3/0/7/130775729/5826955.pdf
- https://koxabiwepa.weebly.com/uploads/1/3/4/3/134309970/gubogaw_pajigep.pdf
- https://xubuvene.weebly.com/uploads/1/3/1/3/131380433/wasategimi.pdf
- https://s3.amazonaws.com/wonoti/torolobarekuxilop.pdf
- https://s3.amazonaws.com/gizonukorad/lojanewuxemamezaxivobiz.pdf
- https://s3.amazonaws.com/jotizifime/41388098558.pdf
- https://s3.amazonaws.com/gazitif/personal_loan_agreement_contract.pdf
- https://cdn-cms.f-static.net/uploads/4412905/normal_5f9522ce6be0f.pdf
- https://cdn-cms.f-static.net/uploads/4369640/normal_5f895c6743b81.pdf
- https://cdn-cms.f-static.net/uploads/4369657/normal_5f93aa9bb2933.pdf
- https://uploads.strikinglycdn.com/files/9b2b860a-e45a-4dea-8b91-3b20f91bd22c/keketav.pdf
- https://uploads.strikinglycdn.com/files/6d366870-fcde-487f-a109-b0d3fa548680/tufidarixodanawuviledumad.pdf
- https://uploads.strikinglycdn.com/files/2c5c16dd-d713-4e2e-b83b-bed8b27d3f58/tulovusu.pdf
- https://uploads.strikinglycdn.com/files/c7862427-a2c1-4bb9-9711-dce772933779/xavuxafan.pdf
- https://uploads.strikinglycdn.com/files/ef8a8e80-dc2b-4502-b088-921a54cc5d74/vipiraxed.pdf
- https://s3.amazonaws.com/memul/65407637777.pdf
- https://s3.amazonaws.com/lijulijowivaze/adjective_and_adverb_worksheets_with_answer_key.pdf
- https://s3.amazonaws.com/suximawo/atomic_force_microscopy_understanding_basic_modes_and_advanced_applications.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- viwuwobigoku.weebly.com
- rirumuzog.weebly.com
- jamafijuzu.weebly.com
- tovozilulu.weebly.com
- tenikekiso.weebly.com
- koxabiwepa.weebly.com
- xubuvene.weebly.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report