SUSPICIOUS — mizopobudadikogolofa.pdf
SUSPICIOUS — mizopobudadikogolofa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
1dba1ea0f7ec0040427001df0ad1fd5a22a0e1909a151833b735664902a5609d - SHA-1:
65a6a8a4fdcc69a15dd2c7f5b0d4ef990eab55dd - MD5:
dec9db0a436f054656bb900f49db0d90 - ssdeep:
768:7gGzpDwSsdZ8EkMzA81uNsl3Ca2BfCz5hJGM4EqYLiuul:EGFkLlkLku9VCnnqYLiuul - TLSH:
T10731AEF3516BCC88B785AF077EE605546156CB8C6132A66069887B7CD0BCBFC6E01E60 - Submitted as: mizopobudadikogolofa.pdf
- File type: pdf · Size: 42526 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=rocket+science+for+traders+digital+signal+processing+applications+pdf, https://site-1037202.mozfiles.com/files/1037202/14357808551.pdf, https://site-1037184.mozfiles.com/files/1037184/8947861325.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=rocket+science+for+traders+digital+signal+processing+applications+pdf
- https://site-1037202.mozfiles.com/files/1037202/14357808551.pdf
- https://site-1037184.mozfiles.com/files/1037184/8947861325.pdf
- https://site-1037079.mozfiles.com/files/1037079/zevepogopizadev.pdf
- https://cdn.shopify.com/s/files/1/0485/9638/5957/files/from_the_previous_article_yellow_perch_in_lake_winnipeg.pdf
- https://site-1040766.mozfiles.com/files/1040766/jekeziwobokesuwid.pdf
- https://site-1038605.mozfiles.com/files/1038605/12577245162.pdf
- https://site-1036751.mozfiles.com/files/1036751/dureriluwemirefesubo.pdf
- http://files.lbvc.co.uk/uploads/1/3/1/4/131437530/mogivotu-wigef-juloforukogugew-delagiwabig.pdf
- http://files.forgiveninchrist.net/uploads/1/3/0/8/130873872/8cc85f2255ca.pdf
- http://files.smilinggrape.com/uploads/1/3/1/6/131637077/8487795.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1037202.mozfiles.com
- site-1037184.mozfiles.com
- site-1037079.mozfiles.com
- cdn.shopify.com
- site-1040766.mozfiles.com
- site-1038605.mozfiles.com
- site-1036751.mozfiles.com
- files.lbvc.co.uk
- files.forgiveninchrist.net
- files.smilinggrape.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report