SUSPICIOUS — watermark_files_linux.pdf
SUSPICIOUS — watermark_files_linux.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
b9cf1f418bbc0c49923616352c8498d868f0be81aee3012af1942abd17cc4e7d - SHA-1:
7ae3d243c73e11904c78c0e90e5911a16d92cdc9 - MD5:
59282882d44bb2116fcdf364da9f85c6 - ssdeep:
768:KgGzpDsea1BvZUD9Ps4Ex1efOVlgrg0p+xgw7NYn9mCVWtDgBP:XGFQea185lEPeyksNQ9mgmDgBP - TLSH:
T10F338DF38097ED8C7A8F6F57ADA7105D954E838C613296A045C8B62CC0BC6EE6F10A51 - Submitted as: watermark_files_linux.pdf
- File type: pdf · Size: 47799 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=watermark+pdf+files+linux, https://pebiname.weebly.com/uploads/1/3/1/4/131453048/mudewojodiroxowu.pdf, https://povutepumik.weebly.com/uploads/1/3/2/7/132741486/lejegumonivixaro.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=watermark+pdf+files+linux
- https://pebiname.weebly.com/uploads/1/3/1/4/131453048/mudewojodiroxowu.pdf
- https://povutepumik.weebly.com/uploads/1/3/2/7/132741486/lejegumonivixaro.pdf
- https://zuwumepegowivos.weebly.com/uploads/1/3/1/0/131069935/2566094.pdf
- https://tudupumodowi.weebly.com/uploads/1/3/1/4/131406798/vixezuxapa-texewenagig-dewuxukazavi.pdf
- https://pukotegifo.weebly.com/uploads/1/3/0/8/130874060/ratuzoruked.pdf
- https://jawowigo.weebly.com/uploads/1/3/0/7/130774982/2841583.pdf
- https://uploads.strikinglycdn.com/files/f9b0bfd5-6be8-414a-8fb2-36c2812728b3/88337084006.pdf
- https://uploads.strikinglycdn.com/files/ab70a200-5de4-44f4-9c17-45c566ab1a8b/90709417867.pdf
- https://uploads.strikinglycdn.com/files/78425711-f915-45fa-8cd5-e29cfc40c096/linasoxojomipebo.pdf
- https://uploads.strikinglycdn.com/files/a1a016f3-e110-46bc-8d4f-c19e4d663191/72183190345.pdf
- https://uploads.strikinglycdn.com/files/f8bfc387-66ed-4090-a0c6-3183a9be8d9b/88483050308.pdf
- https://uploads.strikinglycdn.com/files/8c996f09-faad-4624-b31b-79977757ab4a/xaridigajememovoxureju.pdf
- https://uploads.strikinglycdn.com/files/3587ec6e-df93-4855-886f-0bae4d0b4fc8/zafiliziluxuwi.pdf
- https://uploads.strikinglycdn.com/files/1e29f56e-5584-462c-b924-f7bbae2a7e5e/fosila.pdf
- https://uploads.strikinglycdn.com/files/515673b2-3edc-4260-9351-bb99a0a1981a/soporonugebomifuf.pdf
- https://uploads.strikinglycdn.com/files/e5ce29ae-50cb-4b9e-9a6c-6912af02e292/xizitabovixi.pdf
- https://uploads.strikinglycdn.com/files/4166f4db-2df8-4263-afc6-7e731f755e17/58244254927.pdf
- https://uploads.strikinglycdn.com/files/923f00dc-94d9-4f79-a2bd-18207752503e/tutunemapabujirixunid.pdf
- https://cdn.shopify.com/s/files/1/0505/9117/0725/files/colagem_de_fotos_stories_android.pdf
- https://cdn.shopify.com/s/files/1/0437/8188/2013/files/go_math_7th_grade_curriculum.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- pebiname.weebly.com
- povutepumik.weebly.com
- zuwumepegowivos.weebly.com
- tudupumodowi.weebly.com
- pukotegifo.weebly.com
- jawowigo.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report