SUSPICIOUS — raxodewumonimutuzevo.pdf
SUSPICIOUS — raxodewumonimutuzevo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
b3b1fc165478e29c0ddd21ddf7cb27d5fe5666d027424ac056dfb9513c828b6a - SHA-1:
bf6bd9a2eaa3788b715c4b08c15a1d09c6abf333 - MD5:
f29fa28a167936dcb3343802db7413c5 - ssdeep:
768:FgGzpDLfBnkjjMl4zE3+rvgIfs65lSe6UNPXFLzpB6+yrfrCANeaQ/Ko8/sWzwgV:WGFHJJ3Cvx5o2NRP6+yrzCAXYK+Wrz - TLSH:
T1C5339EF35087DDC8AE8BAF4799A61094604AC7CD71659AA018CD7A3CC87C6FC6E40A60 - Submitted as: raxodewumonimutuzevo.pdf
- File type: pdf · Size: 50800 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=megapolis+cheat+engine+6.+2, https://uploads.strikinglycdn.com/files/2bfadc20-061c-4b79-a5f8-9be9b8c3015b/komoroduj.pdf, https://uploads.strikinglycdn.com/files/90159db3-e811-45b4-bc77-d6e53dbf454e/76518957092.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=megapolis+cheat+engine+6.+2
- https://uploads.strikinglycdn.com/files/2bfadc20-061c-4b79-a5f8-9be9b8c3015b/komoroduj.pdf
- https://uploads.strikinglycdn.com/files/90159db3-e811-45b4-bc77-d6e53dbf454e/76518957092.pdf
- https://uploads.strikinglycdn.com/files/c4de45a9-762d-46ca-a144-e92d76c134b9/23720003821.pdf
- https://uploads.strikinglycdn.com/files/7c8f703e-5d01-43f2-9c69-1551c626c68e/mededekafipog.pdf
- https://uploads.strikinglycdn.com/files/5dc9b6c8-d4bd-4bca-9d0c-ac16c9813413/torozasebu.pdf
- https://uploads.strikinglycdn.com/files/6a1fbdb0-ac48-43d0-ba77-bc803ae4b2d6/minosimuzebofejaja.pdf
- http://files.punchslidedesign.com/uploads/1/3/2/7/132712514/jisisubemi.pdf
- http://files.newleaforganizingllc.com/uploads/1/3/1/8/131857071/6418065.pdf
- https://uploads.strikinglycdn.com/files/32e0109f-3674-4eb1-a435-bec352c909fb/xinepudomatileme.pdf
- https://uploads.strikinglycdn.com/files/72f025f9-7174-4223-8c6d-95bd73f5433b/riwelegusirirokajodevunul.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- files.punchslidedesign.com
- files.newleaforganizingllc.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report