SUSPICIOUS — 61182679516.pdf
SUSPICIOUS — 61182679516.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
c6bfbf400274a3e0b40e6aeac2cbb2bde2229eb87f61c605bb5b157beceaa833 - SHA-1:
3cc409fbddf06c6f95e6f43506582179621dfaa9 - MD5:
ecf08fb8d1d90bb09218f15783e2b42a - ssdeep:
768:uqgGzpD+eudLRz6j4XIrRzioFtN49e2AkvPYoE8//8CM20g56CVWQMuRT:4GFiecA42dik2Zn/8CLZ56gfMuRT - TLSH:
T17C338EF350A3EC8C76CB5B139DAB119E618AC749A1329BA0484C7B2CD4BC6FD6F10915 - Submitted as: 61182679516.pdf
- File type: pdf · Size: 51941 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=cambridge+english+preliminary+%2528pet%2529+pdf, https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/lokujevu.pdf, https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/rezareludufiven-voxodopi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=cambridge+english+preliminary+%2528pet%2529+pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/lokujevu.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/rezareludufiven-voxodopi.pdf
- https://vamekatowozi.weebly.com/uploads/1/3/0/8/130814347/fiferekalu_wudoruliri_ripatinivajewu.pdf
- https://vimiwegom.weebly.com/uploads/1/3/0/7/130775837/vigozajupiwadalelek.pdf
- https://ritibamubube.weebly.com/uploads/1/3/1/4/131437410/pukoxatufu.pdf
- https://cdn-cms.f-static.net/uploads/4366377/normal_5f88d1fa8d1f5.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f88fac5bc95c.pdf
- https://cdn-cms.f-static.net/uploads/4367268/normal_5f87768c20001.pdf
- https://cdn-cms.f-static.net/uploads/4366033/normal_5f870910671e8.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/gapovowumepekegosiza.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/5d6f2da.pdf
- https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/nupunitapubib.pdf
- https://wetuxabo.weebly.com/uploads/1/3/0/8/130873937/tazeraxif.pdf
- https://folarudivol.weebly.com/uploads/1/3/1/8/131871739/959b581.pdf
- https://xebikazogede.weebly.com/uploads/1/3/2/7/132740990/b14c538121.pdf
- https://tiwilofudux.weebly.com/uploads/1/3/1/6/131606348/3414435.pdf
- https://netulomite.weebly.com/uploads/1/3/2/8/132814473/869207.pdf
- https://varipejat.weebly.com/uploads/1/3/0/7/130739080/nuwekixemuwirab.pdf
- https://site-1043763.mozfiles.com/files/1043763/3268845971.pdf
- https://site-1043098.mozfiles.com/files/1043098/rufapotamidozifuze.pdf
- https://site-1041284.mozfiles.com/files/1041284/vijom.pdf
- https://site-1043767.mozfiles.com/files/1043767/38250901520.pdf
- https://site-1048481.mozfiles.com/files/1048481/nusetuwaz.pdf
- https://site-1043081.mozfiles.com/files/1043081/dafek.pdf
Embedded domains
- gettraff.ru
- keniwuki.weebly.com
- vuxozajuje.weebly.com
- vamekatowozi.weebly.com
- vimiwegom.weebly.com
- ritibamubube.weebly.com
- cdn-cms.f-static.net
- genigudepa.weebly.com
- kabudededawizo.weebly.com
- wetuxabo.weebly.com
- folarudivol.weebly.com
- xebikazogede.weebly.com
- tiwilofudux.weebly.com
- netulomite.weebly.com
- varipejat.weebly.com
- site-1043763.mozfiles.com
- site-1043098.mozfiles.com
- site-1041284.mozfiles.com
- site-1043767.mozfiles.com
- site-1048481.mozfiles.com
- site-1043081.mozfiles.com
- site-1042187.mozfiles.com
- site-1042716.mozfiles.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report