SUSPICIOUS — pitorudalogixud.pdf
SUSPICIOUS — pitorudalogixud.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
901e89ba98b73841514cb556b769349737e371405ed8e4f46a541d46578ab476 - SHA-1:
d09853e47b696dc01129177fd603e4fc053c1f0b - MD5:
e7a725508bc63f7143645efc85f2c9ac - ssdeep:
384:TsFlS3K6XgKV7cAgdOpW+0RUd0Y1yNLklIa3DNstRi1l4BSTJ/911UlD/hwpoQdB:vgGzpDE80Y4wdsNCR7vOQ3I3KzApdI - TLSH:
T15F31ACF751A7EC8C7D83AB43ADA600985149C78C213386705988B77ED87C5FDBE20A61 - Submitted as: pitorudalogixud.pdf
- File type: pdf · Size: 40280 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=job+interview+skills+worksheet, https://uploads.strikinglycdn.com/files/1ce467f6-803b-460a-b7d7-51647c4c43b1/12398658679.pdf, https://uploads.strikinglycdn.com/files/48d97e98-3288-4e02-a487-565119042fc2/62114402146.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=job+interview+skills+worksheet
- https://uploads.strikinglycdn.com/files/1ce467f6-803b-460a-b7d7-51647c4c43b1/12398658679.pdf
- https://uploads.strikinglycdn.com/files/48d97e98-3288-4e02-a487-565119042fc2/62114402146.pdf
- https://uploads.strikinglycdn.com/files/25c4fdc2-8a53-4318-8b0f-ff5af3541b89/bosudugisadebanokomo.pdf
- https://uploads.strikinglycdn.com/files/ef08ed56-f54a-4c31-a7c2-33a7e2ff22fc/57858095213.pdf
- https://uploads.strikinglycdn.com/files/722b2d77-0160-4233-95c7-0be2bdee3285/zawenawiwasazatinus.pdf
- https://uploads.strikinglycdn.com/files/d35d3597-063c-4f54-acd5-db5ff169b426/pewalijo.pdf
- https://uploads.strikinglycdn.com/files/56d02ae4-021b-4805-8b37-7917cc7ab9fe/5505518779.pdf
- https://uploads.strikinglycdn.com/files/7827d2d0-30c7-4f40-b78f-70dbaefd860a/kosagamodubazadava.pdf
- https://uploads.strikinglycdn.com/files/f9ae8f2a-150e-4212-ad74-f6a1722c412b/ruvax.pdf
- https://uploads.strikinglycdn.com/files/746810d9-3831-41af-bcdd-b5b0c940faa7/886121036.pdf
- http://luwadero.352coaching.com/uploads/1/3/2/6/132696147/a614eb510.pdf
- http://soxeba.joeysblogspot.com/uploads/1/3/0/8/130814017/rikigidubeneboz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- luwadero.352coaching.com
- soxeba.joeysblogspot.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report