SUSPICIOUS — silerelevibigiwe.pdf
SUSPICIOUS — silerelevibigiwe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
c582d9e53d48aa97212acad33ec6d71c9b1f5206b84fa1e0713eb901af51384e - SHA-1:
4b46ff9aba0b048ede7cc53bd2d0e8c95c34a890 - MD5:
d5bc7aaf12ca560cc390f27158372a5e - ssdeep:
768:KgGzpDFseCUfLvVG6+ESVNRHHiyD0nYPRFgYFJp61hnRAmAt11Y8p:XGF5kPT9FJMnAmAtXY8p - TLSH:
T17D318DF74097ED4CBB4B9B037DAB11A66489D788A132EB614488736CD4BC6BD7E10890 - Submitted as: silerelevibigiwe.pdf
- File type: pdf · Size: 40244 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=google+sheets+insert+multiple+columns, https://cdn.shopify.com/s/files/1/0483/3227/5865/files/55734966989.pdf, https://cdn-cms.f-static.net/uploads/4367268/normal_5f87760f2ce98.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=google+sheets+insert+multiple+columns
- https://cdn.shopify.com/s/files/1/0483/3227/5865/files/55734966989.pdf
- https://cdn-cms.f-static.net/uploads/4367268/normal_5f87760f2ce98.pdf
- https://cdn.shopify.com/s/files/1/0502/0362/3585/files/pedigree_chum_dog_food_feeding_guide.pdf
- https://cdn.shopify.com/s/files/1/0498/7286/3399/files/business_plan_grade_10.pdf
- https://cdn.shopify.com/s/files/1/0481/4857/8471/files/luxubajolunuzukivipod.pdf
- https://bilewobadazape.weebly.com/uploads/1/3/2/6/132695578/zerujenaxatukep.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/kezupukono.pdf
- https://cdn.shopify.com/s/files/1/0502/7201/0389/files/73301846198.pdf
- https://cdn.shopify.com/s/files/1/0435/1747/7019/files/47831000430.pdf
- https://cdn.shopify.com/s/files/1/0498/4717/3286/files/fgo_summer_event_2020_guide_jp.pdf
- https://cdn-cms.f-static.net/uploads/4367621/normal_5f90694b95100.pdf
- https://cdn-cms.f-static.net/uploads/4379476/normal_5f8bfd0cc9a77.pdf
- https://cdn.shopify.com/s/files/1/0502/9871/6324/files/rustoleum_auto_paint_clear_coat.pdf
- https://cdn.shopify.com/s/files/1/0484/8094/4289/files/lp_kanker_nasofaring.pdf
- https://cdn-cms.f-static.net/uploads/4366362/normal_5f8cfd63d5a23.pdf
- https://cdn-cms.f-static.net/uploads/4389601/normal_5f9051f624df8.pdf
- https://jirunemopisitex.weebly.com/uploads/1/3/4/3/134332051/bekekaz-govegovoseku-bapizino.pdf
- https://cdn-cms.f-static.net/uploads/4366033/normal_5f8701d080cf9.pdf
- https://cdn.shopify.com/s/files/1/0268/8306/3986/files/49730874164.pdf
- https://matubupediguja.weebly.com/uploads/1/3/4/1/134131452/lizokitut_kikemowajuv_mapuvigutez_jopidibu.pdf
- https://cdn-cms.f-static.net/uploads/4368984/normal_5f89874c34411.pdf
- https://cdn.shopify.com/s/files/1/0478/1113/3599/files/lusutib.pdf
- https://cdn.shopify.com/s/files/1/0433/4790/2623/files/dozededutupesodopajiwi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- bilewobadazape.weebly.com
- bedizegoresupa.weebly.com
- jirunemopisitex.weebly.com
- matubupediguja.weebly.com
- www.google.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report