SUSPICIOUS — nerutokewozutiz.pdf
SUSPICIOUS — nerutokewozutiz.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
706776ddd441cc550b1b1d3fa6086691448ab5e7b34d1107dd1e605c6b2380e6 - SHA-1:
07b282d5164ec0fc85307b933c10234a8fd079c4 - MD5:
f5c1a4ac7fa4cb737914c2c2786efd4a - ssdeep:
768:HgGzpDc5B1kPHxt05EvEBHJ5bwaEmTvgpGVzYiZ5k9jWvwJS:AGFY6/eujSI0zY+k9ywJS - TLSH:
T1F132ADF341ABEC8C2A97AF4379EA258D6049C3486133E76044C9BB6CC57C3BD6E11960 - Submitted as: nerutokewozutiz.pdf
- File type: pdf · Size: 46342 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=catechism+of+the+catholic+church+pdf+full, http://kixezi.hmoniquedesigns.com/uploads/1/3/1/4/131453915/fonilagimebaw-vatonu-vipukutab-regesutos.pdf, http://files.truthfinderspi.com/uploads/1/3/0/7/130739718/606b91c567.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=catechism+of+the+catholic+church+pdf+full
- http://kixezi.hmoniquedesigns.com/uploads/1/3/1/4/131453915/fonilagimebaw-vatonu-vipukutab-regesutos.pdf
- http://files.truthfinderspi.com/uploads/1/3/0/7/130739718/606b91c567.pdf
- http://gamivo.jayenn.com/uploads/1/3/1/3/131383544/sovexibebamur-nudegotumunas.pdf
- https://site-1048452.mozfiles.com/files/1048452/rijaxitatupimepu.pdf
- https://site-1038611.mozfiles.com/files/1038611/laxub.pdf
- http://files.schoeneheimat.com/uploads/1/3/0/8/130874413/bekebike.pdf
- http://nafubapu.artisanfarmsbreeding.com/uploads/1/3/0/8/130813840/rawixiz.pdf
- http://files.joeinns.com/uploads/1/3/1/0/131071043/7563480.pdf
- http://dilawim.cybercats5436.com/uploads/1/3/1/4/131406379/mirobidofuginik-jiderevoro-gufofeserel-nobud.pdf
- http://files.donrayart.com/uploads/1/3/1/4/131454106/ff40f380f2b.pdf
- http://fadono.videosparks.net/uploads/1/3/0/8/130813332/vipof-fugarari.pdf
- http://files.elishebahouse.com/uploads/1/3/0/7/130775704/piwurobusamoj-sewex-mesifogux-mopumejokaza.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- kixezi.hmoniquedesigns.com
- files.truthfinderspi.com
- gamivo.jayenn.com
- site-1048452.mozfiles.com
- site-1038611.mozfiles.com
- files.schoeneheimat.com
- nafubapu.artisanfarmsbreeding.com
- files.joeinns.com
- dilawim.cybercats5436.com
- files.donrayart.com
- fadono.videosparks.net
- files.elishebahouse.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report