SUSPICIOUS — jetoduwawukumewuserez.pdf
SUSPICIOUS — jetoduwawukumewuserez.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
dcc7226e1cf83e47d25927a4e4bbb6a9e23568382fd7c608b140223afb84029c - SHA-1:
93817137ff317008568666dcffcde2362db548c8 - MD5:
234bb5210d947bcd16327bea5840ff7a - ssdeep:
768:ggGzpDgX8Uzp2DY0ObBEIhS/R/xZcERcbwucEE5iGpSTbOR3IEAmm:tGFUMUzUDbO1EIhS/EVcEEIGUTaiBmm - TLSH:
T1D5329EF351B7ED8C398AAB07ADFA2469544AD3492166D7B488C8772DC4BC33E3E00951 - Submitted as: jetoduwawukumewuserez.pdf
- File type: pdf · Size: 46355 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=ged+certificate+template+pdf, https://uploads.strikinglycdn.com/files/0d607d7d-a367-40d7-a63f-285896555813/79216177225.pdf, https://uploads.strikinglycdn.com/files/c34c1c3c-7d37-4b64-8a6a-81dcba7cedd9/bedor.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=ged+certificate+template+pdf
- https://uploads.strikinglycdn.com/files/0d607d7d-a367-40d7-a63f-285896555813/79216177225.pdf
- https://uploads.strikinglycdn.com/files/c34c1c3c-7d37-4b64-8a6a-81dcba7cedd9/bedor.pdf
- https://uploads.strikinglycdn.com/files/e2f7513d-ad10-4504-8d49-2fb50f43436c/vomibagozedosikegefit.pdf
- https://uploads.strikinglycdn.com/files/f3d9436a-21a5-4296-a083-a6969c2ac7a2/43014487263.pdf
- https://uploads.strikinglycdn.com/files/edda6e4c-d837-49cb-a778-99b23617caf0/belamijuxilokupozobeb.pdf
- https://uploads.strikinglycdn.com/files/1d6da4d4-3d3a-4968-937f-b84584ea8e63/45799449803.pdf
- https://uploads.strikinglycdn.com/files/e8b8eb98-febe-436c-b624-334ee0f7cb0c/21872932991.pdf
- https://uploads.strikinglycdn.com/files/aaa4f0c0-528d-4a63-8e56-1853e19af62d/25492912891.pdf
- https://uploads.strikinglycdn.com/files/aae5e74c-5375-4b32-a089-dc6ae87998f9/61746519229.pdf
- http://files.edgertonbookfestival.org/uploads/1/3/0/9/130970004/3669035.pdf
- http://xelojuzuv.missdivakurves.com/uploads/1/3/2/6/132695384/cff530c8.pdf
- http://xegovupe.sheroamswild.com/uploads/1/3/0/9/130969754/pujowus.pdf
- http://doselofe.mountaintechnicalsolutions.com/uploads/1/3/2/6/132696067/437f979bba74698.pdf
- http://files.modernacupunctureancientmedicine.com/uploads/1/3/1/8/131871518/c0a07437e43.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- files.edgertonbookfestival.org
- xelojuzuv.missdivakurves.com
- xegovupe.sheroamswild.com
- doselofe.mountaintechnicalsolutions.com
- files.modernacupunctureancientmedicine.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report