SUSPICIOUS — pitarizazavirefivuka.pdf
SUSPICIOUS — pitarizazavirefivuka.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
bb040b0890485269fee56e2a887bfe0266e92ac7d3f134ced2b5d51be23f289b - SHA-1:
b733d288d7cf088f5fed6969f3469e89d438d012 - MD5:
96d05b7e338f5c577040fb06aa0467ad - ssdeep:
768:6gGzpD1l773Zqe/Ut895R9+NWphg2HgR/nPY8SxoT:nGF5l73AMu8Pc+hgSg9ntSxoT - TLSH:
T11F329EF38053ED4C7A8B6F07ADE625589086CB882137926454C8777DD07C6EEBF50A22 - Submitted as: pitarizazavirefivuka.pdf
- File type: pdf · Size: 45001 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=financial+analysis+report+using+ratios, https://site-1036651.mozfiles.com/files/1036651/62047810296.pdf, https://site-1037184.mozfiles.com/files/1037184/51094219717.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=financial+analysis+report+using+ratios
- https://site-1036651.mozfiles.com/files/1036651/62047810296.pdf
- https://site-1037184.mozfiles.com/files/1037184/51094219717.pdf
- https://site-1037035.mozfiles.com/files/1037035/69368427172.pdf
- https://site-1037833.mozfiles.com/files/1037833/14891494027.pdf
- https://site-1037893.mozfiles.com/files/1037893/faxozukekowufitazulimi.pdf
- https://uploads.strikinglycdn.com/files/b5546408-a1f3-4ac6-a817-f5c311c85da8/vibibademokesas.pdf
- https://uploads.strikinglycdn.com/files/fa4a21f2-f563-4333-b877-2157e35c0fae/bakividasizagide.pdf
- https://uploads.strikinglycdn.com/files/33476a5f-79fb-4c7b-ab36-ac9be8fd70db/fojurafinujemive.pdf
- https://uploads.strikinglycdn.com/files/a3ce95f7-549b-4cee-a03c-b67ae95f10d1/2875642109.pdf
- https://uploads.strikinglycdn.com/files/4a2eb27c-223e-4b50-8898-d33dcb16d80a/suvizijuvexidifakirinukop.pdf
- http://files.gillysalmon.com/uploads/1/3/0/8/130874516/6d4cf65a76.pdf
- http://files.kyliekissel.com/uploads/1/3/1/4/131407370/nonanobinavijezo.pdf
- http://files.begegnungspraxis.at/uploads/1/3/0/8/130874583/3138784.pdf
- http://zoroka.princeleadershipgroup.com/uploads/1/3/0/8/130874569/poxoxo_tisov_geragidawidini_bataruliraliduk.pdf
- https://uploads.strikinglycdn.com/files/19b97b9e-2b44-4030-9b13-e0b1ccdddc0d/segapivudenifatitar.pdf
- https://uploads.strikinglycdn.com/files/568c7064-aed1-4e29-8a75-7e3bf7893eed/sologi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1036651.mozfiles.com
- site-1037184.mozfiles.com
- site-1037035.mozfiles.com
- site-1037833.mozfiles.com
- site-1037893.mozfiles.com
- uploads.strikinglycdn.com
- files.gillysalmon.com
- files.kyliekissel.com
- zoroka.princeleadershipgroup.com
- www.w3.org
- purl.org
- ns.adobe.com
- files.begegnungspraxis.at
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report