SUSPICIOUS — merowejefinerisa.pdf
SUSPICIOUS — merowejefinerisa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
cfae80608c4b1d4b59adaeaed197516dacf0a6add2df5dd8a590ef854009f0f9 - SHA-1:
4969a14159b754618229368bdb31021c66b28f85 - MD5:
c4b838bc306313d76fbd19c45b69b73c - ssdeep:
768:04gGzpDpSPkbukdSJNa230NZEJwOSvdeq6/8BYqAPdTRhqcMTziOnlB6PtNLsaX:2GFFLLSiEJwhvdt6/kMTRhqcMEtNLsaX - TLSH:
T110318DF3509BECCC6AC69B43ADA201966596C34D723697A099C8777CC87C2FC6F10861 - Submitted as: merowejefinerisa.pdf
- File type: pdf · Size: 43114 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=signos+y+sintomas+del+alzheimer+pdf, http://files.aspencreekcookies.com/uploads/1/3/0/8/130873893/9997832.pdf, http://files.clomudrik.com/uploads/1/3/1/3/131383751/263b93.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=signos+y+sintomas+del+alzheimer+pdf
- http://files.aspencreekcookies.com/uploads/1/3/0/8/130873893/9997832.pdf
- http://files.clomudrik.com/uploads/1/3/1/3/131383751/263b93.pdf
- http://files.arttherapypedalers.com/uploads/1/3/1/8/131871692/4035296.pdf
- http://files.verticalbikeracks.com/uploads/1/3/1/4/131437464/6698723.pdf
- http://files.rockcreekgoldenirish.com/uploads/1/3/1/8/131856907/bozareneve.pdf
- http://silefe.jihyunhong.com/uploads/1/3/0/8/130814687/zizeginomuxavegi.pdf
- http://files.hyperformancellc.com/uploads/1/3/2/6/132680967/vekakogutuz_xadasojogu.pdf
- http://butajode.baxterthetravelguy.com/uploads/1/3/1/3/131379899/tutugufag_pudak_mobekejulomumis.pdf
- http://tibama.wlprep.org/uploads/1/3/0/7/130739893/rasanawumawa-nanolofomubek.pdf
- http://files.lisestrykerstoessel.com/uploads/1/3/1/3/131384660/lotari.pdf
- http://vikirowow.caitlintrude.com/uploads/1/3/0/7/130775403/d50f4e3c6e73f4.pdf
- http://files.stevepullinger.com/uploads/1/3/1/4/131406846/lovubofunisu-pegawujekoze.pdf
- http://betikin.bkdoula.com/uploads/1/3/0/8/130813780/lilumitij.pdf
- http://likege.sweetlandcoffee.com/uploads/1/3/0/7/130740013/4195513.pdf
- http://files.shanellkitt.com/uploads/1/3/1/3/131398185/8afee3.pdf
- http://files.anthonymichaelscatering.com/uploads/1/3/1/4/131453114/vovabajuko.pdf
- http://tikot.madisonarttherapy.com/uploads/1/3/0/8/130814623/puwew_vizole_bosugupilamex.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- files.aspencreekcookies.com
- files.clomudrik.com
- files.arttherapypedalers.com
- files.verticalbikeracks.com
- files.rockcreekgoldenirish.com
- silefe.jihyunhong.com
- files.hyperformancellc.com
- butajode.baxterthetravelguy.com
- tibama.wlprep.org
- files.lisestrykerstoessel.com
- vikirowow.caitlintrude.com
- files.stevepullinger.com
- betikin.bkdoula.com
- likege.sweetlandcoffee.com
- files.shanellkitt.com
- files.anthonymichaelscatering.com
- tikot.madisonarttherapy.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report