SUSPICIOUS — kuvimup-rusotoxujuredod-ralirupumup-luximujovozi.pdf
SUSPICIOUS — kuvimup-rusotoxujuredod-ralirupumup-luximujovozi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 1 of 50 detection engines flagged it.
Identification
- SHA-256:
84ef37fc539c1a188f15771c17f9b914e4875efdd710fa4f0ec318df31fc0333 - SHA-1:
95df409a773a76df66e89111ebe5dfe9e1ce8b23 - MD5:
b9b61e574466b84711a196811dbcbebc - ssdeep:
768:KgGzpDHoeuZ+Nz2CFRGoYfuW9rvIuVnSpKeXywgdJ7NrYMWv/0:XGFketXYt9bIupeCDDNrhWv/0 - TLSH:
T1B8318DF31097EC8C7A8BBF07ADAB156D548AD34D70269BA0158C762CC07CAED7E10A51 - Submitted as: kuvimup-rusotoxujuredod-ralirupumup-luximujovozi.pdf
- File type: pdf · Size: 39448 bytes
- Verdict: suspicious (35/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=sweet%20sinner%20torrent, https://uploads.strikinglycdn.com/files/6d2fdc9a-4db7-4de6-bf1b-6e91d876080d/sijinuwesejevaduzivilu.pdf, https://uploads.strikinglycdn.com/files/646c71cf-12d1-4afa-9b67-67311848d974/19552805409.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=sweet%20sinner%20torrent
- https://uploads.strikinglycdn.com/files/6d2fdc9a-4db7-4de6-bf1b-6e91d876080d/sijinuwesejevaduzivilu.pdf
- https://uploads.strikinglycdn.com/files/646c71cf-12d1-4afa-9b67-67311848d974/19552805409.pdf
- https://uploads.strikinglycdn.com/files/054daa7b-0925-42cf-9198-6332bb93c005/88529614971.pdf
- https://uploads.strikinglycdn.com/files/49cf8146-075a-40a2-af54-7d803c580e5a/balumudojodadapozebe.pdf
- https://cdn-cms.f-static.net/uploads/4369760/normal_5f8880fcab508.pdf
- https://cdn-cms.f-static.net/uploads/4369507/normal_5f89536c9bb75.pdf
- https://uploads.strikinglycdn.com/files/24ba8007-02c4-4441-85ce-08680dab888d/nurokaxavikomomutuj.pdf
- https://uploads.strikinglycdn.com/files/0061854d-bd4b-4ae2-84af-55ee5fdb1eb0/tepotaxoda.pdf
- https://uploads.strikinglycdn.com/files/036fe162-4ed7-4a39-9fc6-aac4890fc66f/chistes_sobre_la_revolucion_mexicana.pdf
- https://uploads.strikinglycdn.com/files/e2219938-d77a-46d9-867b-0f7ceacad771/nadedigezopu.pdf
- https://vixijusodu.weebly.com/uploads/1/3/0/7/130776714/6467039.pdf
- https://polabufasol.weebly.com/uploads/1/3/2/8/132814050/jarakaledo.pdf
- https://gusumadanu.weebly.com/uploads/1/3/2/6/132695601/fetudof-bopinukurane.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/9d013.pdf
- https://kusebedanosude.weebly.com/uploads/1/3/1/1/131163667/vepetobonev-xijegosom.pdf
- https://uploads.strikinglycdn.com/files/30b7428e-c3be-48c0-b21d-9e97ac00d96a/60525723419.pdf
- https://uploads.strikinglycdn.com/files/8ee95cad-3fec-43cf-9d8d-0ba212550a6f/28368057787.pdf
- https://uploads.strikinglycdn.com/files/4f2f5107-4345-4d5d-9944-1ab9e6b2944e/best_book_on_leaky_gut_syndrome.pdf
- https://uploads.strikinglycdn.com/files/05123a6e-ca08-407f-858d-f98b9c152d5d/kisibuvevukifinim.pdf
- https://uploads.strikinglycdn.com/files/06cdb424-b587-4ae9-a7c8-13d7481674a5/lewis_structure_worksheet.pdf
- https://uploads.strikinglycdn.com/files/2292676d-925f-43ff-bff5-62c66ac46ca8/ronipajoroxomet.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- vixijusodu.weebly.com
- polabufasol.weebly.com
- gusumadanu.weebly.com
- wepugimi.weebly.com
- kusebedanosude.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report