SUSPICIOUS — 51938839365.pdf
SUSPICIOUS — 51938839365.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
76dac8b222bace22d26148f69f945987206452c623b11f05c6058919e6c7f870 - SHA-1:
b30b09cbd70cb991ced3f225e3d5fe878c00ed92 - MD5:
673106201c8956c2df55293a6a64cc4c - ssdeep:
768:pgGzpDtH6inIhpXaBGxKEqtpsg43R1QazbzRd/WC5AEc8G99/QJ4j1J:KGF5aYMFqtps1tzbNd/WBEM9NQJ4j1J - TLSH:
T1EE318DF350E7DD487ACB9B03ADAB2565544AE24C6223D76058C87B7DC9BC2BC2F14860 - Submitted as: 51938839365.pdf
- File type: pdf · Size: 42190 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=amendments+to+the+constitution+pdf, https://site-1037241.mozfiles.com/files/1037241/99018915733.pdf, https://site-1037230.mozfiles.com/files/1037230/92608419570.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=amendments+to+the+constitution+pdf
- https://site-1037241.mozfiles.com/files/1037241/99018915733.pdf
- https://site-1037230.mozfiles.com/files/1037230/92608419570.pdf
- https://site-1036988.mozfiles.com/files/1036988/xerixaxobo.pdf
- https://site-1037028.mozfiles.com/files/1037028/32513217755.pdf
- https://uploads.strikinglycdn.com/files/6ec17386-68cc-4c38-badd-566c8e5065a3/50997999040.pdf
- https://uploads.strikinglycdn.com/files/0a5e7dd0-4ff5-4e74-9c9f-30e8d7fc00ca/sufivagarovop.pdf
- https://uploads.strikinglycdn.com/files/ed7eaa05-da4c-489b-bb6f-5d4063559f96/22318053021.pdf
- http://files.hopehf.com/uploads/1/3/2/6/132681343/lejipebelijox.pdf
- http://files.transfig-sm.org/uploads/1/3/0/9/130969204/zapixijexitutugowujo.pdf
- http://wixoga.newtondemocracy.org/uploads/1/3/0/9/130969060/5242099.pdf
- http://files.tickittyshake.com/uploads/1/3/1/8/131857782/poziboruwax.pdf
- http://files.thenauticalartsworkshop.com/uploads/1/3/1/6/131606035/bikebawifutir.pdf
- http://files.peacockmosaics.co.uk/uploads/1/3/0/7/130775361/mapijoriz.pdf
- http://doxiseju.kayscience.com/uploads/1/3/1/8/131857241/jipogejur.pdf
- http://xajoj.elmbankrabbitboarding.com/uploads/1/3/0/9/130969352/fde375.pdf
- http://vibid.melissaradtkepiano.com/uploads/1/3/1/6/131606289/2906286.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1037241.mozfiles.com
- site-1037230.mozfiles.com
- site-1036988.mozfiles.com
- site-1037028.mozfiles.com
- uploads.strikinglycdn.com
- files.hopehf.com
- files.transfig-sm.org
- wixoga.newtondemocracy.org
- files.tickittyshake.com
- files.thenauticalartsworkshop.com
- files.peacockmosaics.co.uk
- doxiseju.kayscience.com
- xajoj.elmbankrabbitboarding.com
- vibid.melissaradtkepiano.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report