SUSPICIOUS — invalid_times_argument_r.pdf
SUSPICIOUS — invalid_times_argument_r.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e9d6e9315e3600efcc48cdadc5d73ba95a2e47ee327db9e821cad22f9d5981e0 - SHA-1:
9060c655ce341bc2920d08a61f0425caa5994cbc - MD5:
694838407b9c2c7b223efa980b4e6dad - ssdeep:
768:GgGzpDfpuBHdiglujjXX/7SCGcEcjhVKsI6Drb4BZFH7fDFcw:TGFTpuHhlUjXP+CuAcsINnJbDFcw - TLSH:
T19F327CF30097EC8C7A8F9F1399AB15ADA18AC78CA137965014DC763CD47CAED2E00665 - Submitted as: invalid_times_argument_r.pdf
- File type: pdf · Size: 45494 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=invalid+times+argument+r, https://tunomofezu.weebly.com/uploads/1/3/2/3/132303147/bujixotaxe.pdf, https://mijisurux.weebly.com/uploads/1/3/1/0/131070147/pebipefuwu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=invalid+times+argument+r
- https://s3.amazonaws.com/befarekogol/aiag_vda_fmea_handbook.pdf
- https://s3.amazonaws.com/bopuxosavubare/internal_audit_plan.pdf
- https://s3.amazonaws.com/jasadavebaga/official_email_writing_tips.pdf
- https://s3.amazonaws.com/gazitif/ampicilina_dosis_neonatal.pdf
- https://s3.amazonaws.com/tosevud/alif_laila_kahani_in_urdu.pdf
- https://s3.amazonaws.com/labitajaxatufib/11709966796.pdf
- https://s3.amazonaws.com/rujabepifar/mythology_stories.pdf
- https://s3.amazonaws.com/bajapovogam/21_cfr_part_114.pdf
- https://tunomofezu.weebly.com/uploads/1/3/2/3/132303147/bujixotaxe.pdf
- https://mijisurux.weebly.com/uploads/1/3/1/0/131070147/pebipefuwu.pdf
- https://rirumuzog.weebly.com/uploads/1/3/4/1/134109041/fb12f6e67.pdf
- https://tovozilulu.weebly.com/uploads/1/3/0/8/130873983/sekamifeperuti.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/runemevurexuziwone.pdf
- https://rikisuluwujufa.weebly.com/uploads/1/3/1/4/131452938/3799729.pdf
- https://tamegafatukof.weebly.com/uploads/1/3/4/4/134400059/pisuf.pdf
- https://wefamojugibe.weebly.com/uploads/1/3/1/1/131164519/1369412.pdf
- https://uploads.strikinglycdn.com/files/f308c411-e0ac-4d0e-b6b2-c95e9196120a/12357910174.pdf
- https://uploads.strikinglycdn.com/files/ca9d578b-0532-41c2-9bf4-f02db2e18e2d/dibedoxurasapama.pdf
- https://uploads.strikinglycdn.com/files/e1d0e3d2-cacb-43e7-9a10-b990202a1b22/40464655681.pdf
- https://uploads.strikinglycdn.com/files/106f08b3-d104-4f07-a774-66a68ca656b7/88431922622.pdf
- https://s3.amazonaws.com/vobuturinivi/anterior_cord_syndrome_adalah.pdf
- https://s3.amazonaws.com/wisuw/introduction_to_arduino_software.pdf
- https://s3.amazonaws.com/belopudevuzuza/48428700113.pdf
- https://s3.amazonaws.com/donake/53819444658.pdf
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- tunomofezu.weebly.com
- mijisurux.weebly.com
- rirumuzog.weebly.com
- tovozilulu.weebly.com
- genigudepa.weebly.com
- rikisuluwujufa.weebly.com
- tamegafatukof.weebly.com
- wefamojugibe.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report