SUSPICIOUS — wirozevowixigezegu.pdf
SUSPICIOUS — wirozevowixigezegu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
a03406e014b00fe6f35253de06d1b713347d6ff9240abe15d4beb14e0a7ec7d5 - SHA-1:
0e5e567071a41870f366743a1f3c6ddc39d72aee - MD5:
9c2b460362c85ceb5e34d1a4b5197563 - ssdeep:
768:6fgGzpD4VJQIWDHla8jKuNTinHN7TJ6Gi2KLZOQlh+w:vGFkVJcut/JW2UZOOh+w - TLSH:
T146329DF3A053DC4CA68B9B0369F7206CA295A649A132E7A0149D77ACD07C7BD3F40875 - Submitted as: wirozevowixigezegu.pdf
- File type: pdf · Size: 44452 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=intrinsic+and+extrinsic+motivation+pdf, https://site-1037866.mozfiles.com/files/1037866/32691654018.pdf, https://site-1040141.mozfiles.com/files/1040141/78408189748.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=intrinsic+and+extrinsic+motivation+pdf
- https://site-1037866.mozfiles.com/files/1037866/32691654018.pdf
- https://site-1040141.mozfiles.com/files/1040141/78408189748.pdf
- https://site-1037914.mozfiles.com/files/1037914/weropesajajuf.pdf
- https://site-1036686.mozfiles.com/files/1036686/60277507759.pdf
- https://cdn.shopify.com/s/files/1/0437/6464/6042/files/dalaran_heist_wick_3_release_date.pdf
- http://files.fullcontactrunner.com/uploads/1/3/1/4/131438079/46c1ce2fd7bb24.pdf
- http://nawevor.inspiredmusic.us/uploads/1/3/1/4/131406211/3e31dbe343a0f60.pdf
- http://files.oneactioncalendar.org/uploads/1/3/1/4/131408970/cc4571ed8.pdf
- http://zutazofog.valweedonmbe.net/uploads/1/3/0/8/130813550/bivebetuzekut.pdf
- https://cdn.shopify.com/s/files/1/0433/5324/3816/files/white_stag_jeans_at_walmart.pdf
- https://cdn.shopify.com/s/files/1/0484/0315/3048/files/ccsd_calendar_2019_colorado.pdf
- https://cdn.shopify.com/s/files/1/0457/7486/4550/files/32467053878.pdf
- https://cdn.shopify.com/s/files/1/0499/4056/2078/files/drivers_license_template_editable.pdf
- https://cdn.shopify.com/s/files/1/0438/5911/6182/files/zoluzurijupakijim.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1037866.mozfiles.com
- site-1040141.mozfiles.com
- site-1037914.mozfiles.com
- site-1036686.mozfiles.com
- cdn.shopify.com
- files.fullcontactrunner.com
- nawevor.inspiredmusic.us
- files.oneactioncalendar.org
- zutazofog.valweedonmbe.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report