SUSPICIOUS — lirupabujunof.pdf
SUSPICIOUS — lirupabujunof.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
7d8655e0d009896b635aee71c5afbd42c8a1688355576faac8ac0cfe5c60c4f0 - SHA-1:
76b0866777e398499d6c85e58456d4bbe7e64346 - MD5:
bba2c3a86f915eefb2fa716e36fefef7 - ssdeep:
768:YgGzpD8HBen0sNEVxPSysi7HLBAMOQa93c+RTCKrWlVAOp/EN76Jl0Y9XOT:1GFIlPfsyrabQR+Rs3p97tXOT - TLSH:
T1DE329EF31097ED8C7B8BAB076EAB025D514AC688A136D7A054CC776DC4BC5ED6E00A60 - Submitted as: lirupabujunof.pdf
- File type: pdf · Size: 44238 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=shodhganga+mathematics+project+pdf, https://uploads.strikinglycdn.com/files/722e04f9-4402-4651-a997-b5647ec8f265/52998663072.pdf, https://uploads.strikinglycdn.com/files/d71707ab-fe0c-4e93-8f1d-c8ac2d7ee4a6/fulaxidewetevitotovesip.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=shodhganga+mathematics+project+pdf
- https://uploads.strikinglycdn.com/files/722e04f9-4402-4651-a997-b5647ec8f265/52998663072.pdf
- https://uploads.strikinglycdn.com/files/d71707ab-fe0c-4e93-8f1d-c8ac2d7ee4a6/fulaxidewetevitotovesip.pdf
- https://uploads.strikinglycdn.com/files/2808e719-aab2-4973-8c2f-502f63511f27/wixem.pdf
- https://uploads.strikinglycdn.com/files/91b9dd73-87af-4cd6-bcfe-2abbc384928f/87369571171.pdf
- https://uploads.strikinglycdn.com/files/ebdd4590-d5d9-4cd9-80aa-45aee321c672/jakanaritudiduk.pdf
- http://files.scurowatches.com/uploads/1/3/1/4/131411987/27bfe78e.pdf
- http://newiji.littlevipschildcare.net/uploads/1/3/2/8/132814343/pupezujuxamafuxuxe.pdf
- http://geliju.infantswimphilly.com/uploads/1/3/0/8/130874455/8754961.pdf
- http://mevoken.liveinfullbloom.org/uploads/1/3/2/6/132695375/puzib_vewuwuvuzuleb_zewoxuzo_kipev.pdf
- https://cdn.shopify.com/s/files/1/0435/8501/1880/files/les_adjuvants_pour_bton.pdf
- https://cdn.shopify.com/s/files/1/0431/5276/9192/files/rural_king_coupons_2020.pdf
- https://cdn.shopify.com/s/files/1/0482/5366/5442/files/joruronugimirabid.pdf
- https://cdn.shopify.com/s/files/1/0430/7173/3917/files/invoice_email_template_free_download.pdf
- https://uploads.strikinglycdn.com/files/ef4fb81b-8c6c-430d-b21f-eec5e3335acf/matopukebeko.pdf
- https://uploads.strikinglycdn.com/files/bd7d15e8-558a-4b21-a7d7-033cafdff51b/38352291878.pdf
- https://uploads.strikinglycdn.com/files/1c28b3d0-ae15-44ea-b171-89e2c5006ddc/pekumulukisezonovaretej.pdf
- https://uploads.strikinglycdn.com/files/896b6ea9-e48d-4328-9bd1-5cbda3caa31a/42024098187.pdf
- https://uploads.strikinglycdn.com/files/2296af4a-c9d9-4c0d-becc-ad28e8b1935a/68593215288.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- files.scurowatches.com
- newiji.littlevipschildcare.net
- geliju.infantswimphilly.com
- mevoken.liveinfullbloom.org
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report