SUSPICIOUS — mekedebudowowexesurikibol.pdf
SUSPICIOUS — mekedebudowowexesurikibol.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
00035ac3f5c272f6aeaedd6ef16680087fcb53286d90a23341deb1723cde48f7 - SHA-1:
75de4ef2c8ce5b449303a712a33547ef201488ef - MD5:
952eadbf5a624096c54f535c147535ff - ssdeep:
1536:cFGFVOTnBUv6ymFd1amrkn4tS0wdjIcLZW0hvkV+C6+Kxhrrr:cYFVO2V81a0kuS0wbYA8VU3j - TLSH:
T18036D0F39153CDCCB5872B47A9A7104CA05AD3C93236A7A014C87A2CC47C7FDAE549A9 - Submitted as: mekedebudowowexesurikibol.pdf
- File type: pdf · Size: 69048 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=chava+book+pdf+free+download, https://site-1037856.mozfiles.com/files/1037856/84203977060.pdf, https://site-1037010.mozfiles.com/files/1037010/16943310282.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=chava+book+pdf+free+download
- https://site-1037856.mozfiles.com/files/1037856/84203977060.pdf
- https://site-1037010.mozfiles.com/files/1037010/16943310282.pdf
- https://site-1036864.mozfiles.com/files/1036864/61466882891.pdf
- http://files.opossumbottom.com/uploads/1/3/0/7/130738914/8533676.pdf
- https://site-1036824.mozfiles.com/files/1036824/fibajijojizisexevomapo.pdf
- https://site-1037103.mozfiles.com/files/1037103/94755495926.pdf
- https://site-1037883.mozfiles.com/files/1037883/50083336622.pdf
- https://uploads.strikinglycdn.com/files/7047977b-fee4-4a0e-8d19-1f745c8dc493/keludodukabak.pdf
- https://uploads.strikinglycdn.com/files/a1dea644-ef16-4c90-b6bc-2323638b9480/89894085832.pdf
- https://uploads.strikinglycdn.com/files/e80606c7-c914-4bb5-84f5-30c50b64898b/22096638121.pdf
- https://uploads.strikinglycdn.com/files/96dea8ba-6d8b-4edf-a893-e2cc18979cf6/fajuxizapuj.pdf
- https://uploads.strikinglycdn.com/files/9751e4d3-327e-42c9-914d-24c21ffb4387/pexegogu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1037856.mozfiles.com
- site-1037010.mozfiles.com
- site-1036864.mozfiles.com
- files.opossumbottom.com
- site-1036824.mozfiles.com
- site-1037103.mozfiles.com
- site-1037883.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report