SUSPICIOUS — 94985591170.pdf
SUSPICIOUS — 94985591170.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
24336842560d683ecf04db5fe4f2f7ee4f74699ec514bea7275c99812fd4c59a - SHA-1:
f18297a6081d2987e9af5f364dccfe3be423b010 - MD5:
0c51986f46de8427f05e81a23b2b1ad3 - ssdeep:
768:ygGzpDOov/s8DI7PUe5SHckvrw01jexNLtSHE8wSi/7lJQ8VBKVNPdR:vGFykHDMV0w01jeFSZwSaQ8eRR - TLSH:
T1DA33BFF305ABDD9C7AC6AB0399BB11295586C38C613387A084C97A7CC47CAFD7D509A0 - Submitted as: 94985591170.pdf
- File type: pdf · Size: 49666 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=spinning+mill+project+report+pdf, https://site-1037180.mozfiles.com/files/1037180/rapimupog.pdf, https://site-1041784.mozfiles.com/files/1041784/xasizakir.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=spinning+mill+project+report+pdf
- https://site-1037180.mozfiles.com/files/1037180/rapimupog.pdf
- https://site-1041784.mozfiles.com/files/1041784/xasizakir.pdf
- https://site-1037163.mozfiles.com/files/1037163/47368605129.pdf
- https://site-1043850.mozfiles.com/files/1043850/42970280496.pdf
- https://site-1036921.mozfiles.com/files/1036921/95276088578.pdf
- http://wodelewoz.robertomasiniluthier.com/uploads/1/3/1/4/131453945/6346bb8ab6.pdf
- https://uploads.strikinglycdn.com/files/eb0e3be6-678f-49aa-a759-1bfc406d29cd/kakakujijod.pdf
- https://uploads.strikinglycdn.com/files/3b9ca842-a3ac-48cd-98a1-3f07b7333f42/10763417236.pdf
- https://uploads.strikinglycdn.com/files/14df3c80-67db-49d2-8ac9-fd63d4d84434/66836552335.pdf
- https://uploads.strikinglycdn.com/files/26431bef-124c-4cad-8867-d8bdfdf549a3/mupubusoj.pdf
- https://uploads.strikinglycdn.com/files/202531bc-7765-4950-8e59-960385882fd4/1387109366.pdf
- https://uploads.strikinglycdn.com/files/4d4b8131-6a2d-4c68-8f6b-8393acf2eca4/xevusefexetobigureni.pdf
- https://uploads.strikinglycdn.com/files/87193240-7d6d-47e8-911c-6fb47a2508a9/jitifelolifitutowigabiwa.pdf
- https://uploads.strikinglycdn.com/files/6cd96f94-2241-4914-833e-0ee17a23d9b3/xolekodujoluvesap.pdf
- https://uploads.strikinglycdn.com/files/2362ff9f-b11d-4086-95da-2c8459d2a428/jekefeninivobibixesade.pdf
- https://uploads.strikinglycdn.com/files/79921f8d-a0ef-446e-a968-0837aa8e8bcc/40184682608.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1037180.mozfiles.com
- site-1041784.mozfiles.com
- site-1037163.mozfiles.com
- site-1043850.mozfiles.com
- site-1036921.mozfiles.com
- wodelewoz.robertomasiniluthier.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report