SUSPICIOUS — kusogivitafanotilezobitak.pdf
SUSPICIOUS — kusogivitafanotilezobitak.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
6d624b72b79df03e68045ae6d5ec4cd39a000bdf14cb0563c7287944ba159f2a - SHA-1:
03060bfbd732c7b217674b2e532c6781704acd73 - MD5:
fb854ee6248cacb28bcbc94e11c6ab89 - ssdeep:
1536:fGF9lzO+j1HN5tzxUeQOEc8KnPwP4w1whSyaIinaJY:OF9lFNUe91nu4wiC/ - TLSH:
T19837CFF7019BED8C77876F036AB610466149DA887533ABA414C8762CC9FC6FC2E11961 - Submitted as: kusogivitafanotilezobitak.pdf
- File type: pdf · Size: 73694 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=myrtle+beach+mugshots+search, https://cdn.shopify.com/s/files/1/0496/1465/1559/files/dajebigexuwodefowu.pdf, https://uploads.strikinglycdn.com/files/4d172fb3-0740-4c29-8254-c04ebc444261/15594221785.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=myrtle+beach+mugshots+search
- https://cdn.shopify.com/s/files/1/0496/1465/1559/files/dajebigexuwodefowu.pdf
- https://uploads.strikinglycdn.com/files/4d172fb3-0740-4c29-8254-c04ebc444261/15594221785.pdf
- https://bodadesoka.weebly.com/uploads/1/3/4/2/134234706/5866889.pdf
- https://s3.amazonaws.com/povodijirig/enrique_y_maria_crossword_answers.pdf
- https://cdn.shopify.com/s/files/1/0435/5407/8871/files/rojukubajegumalon.pdf
- https://rexavinuzuna.weebly.com/uploads/1/3/4/3/134308075/d9ac5099168dd2.pdf
- https://xumuxurubaxuk.weebly.com/uploads/1/3/4/5/134501003/vodaparitonuj.pdf
- https://s3.amazonaws.com/wupixufekijax/19373577325.pdf
- https://lipowuripipu.weebly.com/uploads/1/3/1/3/131378852/jikadiboposaba_sajatufobage.pdf
- https://gejatovuri.weebly.com/uploads/1/3/1/4/131406669/zumajamibapebu.pdf
- https://xonuvalax.weebly.com/uploads/1/3/1/4/131437330/wifaw-kixubedukawab.pdf
- https://uploads.strikinglycdn.com/files/b73bbf89-9414-4b2b-a6a9-0dd102501a28/descargar_eternal_darkness_gamecube_espaol_iso.pdf
- https://xusawoji.weebly.com/uploads/1/3/0/7/130739635/xirenesedato.pdf
- https://s3.amazonaws.com/novipaliwid/miforeraji.pdf
- https://cdn.shopify.com/s/files/1/0496/5453/0204/files/after_tooth_extraction_instructions.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- bodadesoka.weebly.com
- s3.amazonaws.com
- rexavinuzuna.weebly.com
- xumuxurubaxuk.weebly.com
- lipowuripipu.weebly.com
- gejatovuri.weebly.com
- xonuvalax.weebly.com
- xusawoji.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report