SUSPICIOUS — kamoxunanulapefo.pdf
SUSPICIOUS — kamoxunanulapefo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
666d21b35a6edb3291518615008ce5df902f2cf0ebb0a636b88f60f90099e115 - SHA-1:
c2900b414713b29342a617e42d873f6078c53f03 - MD5:
cc6a80441871e6c6ec1c911ad71def27 - ssdeep:
768:VgGzpDKpmozqPVtR4trywqq4QyF6RzlmuGsI4TDN32uQKg0TLYlYFWWZOI:GGFupmkmkmMTDvXPY2wWZOI - TLSH:
T17633AEF755EBED8C79868B47ADAB14E46099C3886132877044CCB72DC4BC6BCAE00D61 - Submitted as: kamoxunanulapefo.pdf
- File type: pdf · Size: 51790 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=vinayaka+chavithi+pooja+telugu+pdf, https://uploads.strikinglycdn.com/files/5700779a-5b38-4b96-80ce-11496a63b4da/69026441185.pdf, https://uploads.strikinglycdn.com/files/a45ef13d-fac4-486f-8b46-c7603f6f821d/gosisuvelefipi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=vinayaka+chavithi+pooja+telugu+pdf
- https://uploads.strikinglycdn.com/files/5700779a-5b38-4b96-80ce-11496a63b4da/69026441185.pdf
- https://uploads.strikinglycdn.com/files/a45ef13d-fac4-486f-8b46-c7603f6f821d/gosisuvelefipi.pdf
- https://uploads.strikinglycdn.com/files/bbdae2ed-f800-4c69-86fd-51e4c7699fae/lesuderizasezes.pdf
- https://uploads.strikinglycdn.com/files/02a58890-6db1-4494-a26f-134b2b5a87fc/lopigotavenu.pdf
- https://cdn-cms.f-static.net/uploads/4366949/normal_5f8a4d1767d1c.pdf
- https://cdn-cms.f-static.net/uploads/4366375/normal_5f8e94b7112f7.pdf
- https://cdn-cms.f-static.net/uploads/4366399/normal_5f8763490667d.pdf
- https://cdn-cms.f-static.net/uploads/4386836/normal_5f8c9b7c5a5a9.pdf
- https://cdn-cms.f-static.net/uploads/4366057/normal_5f8949db78047.pdf
- https://dozasasakebo.weebly.com/uploads/1/3/1/1/131164234/7519535.pdf
- https://sakuvida.weebly.com/uploads/1/3/0/7/130775714/cbb0ca98c903.pdf
- https://wivupenoremew.weebly.com/uploads/1/3/0/7/130775018/378398.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/vunidixeviro_xitosujitupile_kadape.pdf
- https://s3.amazonaws.com/mijedusovineti/administering_medication.pdf
- https://s3.amazonaws.com/zirojopemup/55114501063.pdf
- https://s3.amazonaws.com/tuzamada/69034572598.pdf
- https://s3.amazonaws.com/kavitokolezub/marketing_free_download.pdf
- https://uploads.strikinglycdn.com/files/79c1573f-fa94-409f-b0a5-45ae557cb923/wiribixuxu.pdf
- https://uploads.strikinglycdn.com/files/00ca4d1a-fc5a-4ca6-9a2d-a6c72dab26a6/67888333009.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- dozasasakebo.weebly.com
- sakuvida.weebly.com
- wivupenoremew.weebly.com
- bedizegoresupa.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report