SUSPICIOUS — nawazusujijokiju.pdf
SUSPICIOUS — nawazusujijokiju.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
2fa552b7af37394f0d4fc87e9088d7ab19748e8e90f3e97817eb47c36f2cf5c4 - SHA-1:
050732b2d48381d24d2f390626467c939e20a2cb - MD5:
acf16b74c0d44b293210db218e528338 - ssdeep:
768:RgGzpD/9b+U513CJ45gnmebe+epXyQd95w7uOU7lX6p0VEFcw5y2xIimZC:iGF7T51SJagnPbgpXyQrUU7gpJFcwVxn - TLSH:
T177339FF36097ED8CF68B9B13AEBB1058614BC789213297A05498B72DC47C6FD6E40D60 - Submitted as: nawazusujijokiju.pdf
- File type: pdf · Size: 48604 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=high+school+math+probability+pdf, http://bigavuvaj.westequip.com/uploads/1/3/1/4/131437792/tojabavulexo.pdf, http://files.osgood-lagrone.com/uploads/1/3/1/4/131408930/duzirepola_fevinituze_mifamuxakat_fajazuvikufoso.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=high+school+math+probability+pdf
- http://bigavuvaj.westequip.com/uploads/1/3/1/4/131437792/tojabavulexo.pdf
- http://files.osgood-lagrone.com/uploads/1/3/1/4/131408930/duzirepola_fevinituze_mifamuxakat_fajazuvikufoso.pdf
- http://jafebo.oregoncoastphotoclub.com/uploads/1/3/1/3/131397987/2083024.pdf
- http://files.bate-field.com/uploads/1/3/0/7/130775249/musufabojo-kizetefaxebako-waduros.pdf
- https://uploads.strikinglycdn.com/files/0a67b399-c009-49d6-bd76-8ee3491e2428/46814241682.pdf
- https://uploads.strikinglycdn.com/files/09dfe456-dbf4-4aa2-8eb1-2b84daeab3b0/fezewusaduv.pdf
- https://uploads.strikinglycdn.com/files/ef267af0-f8fb-42cc-a069-eb9036d57735/23728412639.pdf
- https://uploads.strikinglycdn.com/files/4f9e2eab-ba58-4614-a55f-711226d061dd/23760409598.pdf
- https://site-1036696.mozfiles.com/files/1036696/80019920513.pdf
- https://site-1036731.mozfiles.com/files/1036731/12989173501.pdf
- https://site-1036946.mozfiles.com/files/1036946/kazegatorotoruguzu.pdf
- https://site-1037218.mozfiles.com/files/1037218/lalififizivegutase.pdf
- https://site-1036830.mozfiles.com/files/1036830/ruwawuzoxefit.pdf
- https://uploads.strikinglycdn.com/files/4faed4ff-ae0c-4089-bf1d-67e376280784/40387395438.pdf
- https://uploads.strikinglycdn.com/files/c05cbd0e-6ce0-49e5-b391-9cbd0dc2616c/kuwifabero.pdf
- https://uploads.strikinglycdn.com/files/f3aa61de-8618-427c-a134-8f97b39dc9da/fesotikufonufifem.pdf
- https://uploads.strikinglycdn.com/files/37a129b9-7cc2-4211-bc61-136f95a80d15/39639085117.pdf
- https://uploads.strikinglycdn.com/files/faceceff-8314-4406-a60a-47e16298849e/49641773206.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- bigavuvaj.westequip.com
- files.osgood-lagrone.com
- jafebo.oregoncoastphotoclub.com
- files.bate-field.com
- uploads.strikinglycdn.com
- site-1036696.mozfiles.com
- site-1036731.mozfiles.com
- site-1036946.mozfiles.com
- site-1037218.mozfiles.com
- site-1036830.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report