SUSPICIOUS — datanegujakowavul.pdf
SUSPICIOUS — datanegujakowavul.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
7e953305281679780ad77033b47046b8086838507670e14df97d99d873e6962f - SHA-1:
94df36e3bc09c4a180f2f36d07d559629122f3c9 - MD5:
70a2ea22aeb06ad5aa6f53d93de2ef1c - ssdeep:
768:5gGzpDhgHwMWhNBEGZwE8w0Z+A4hVBvLUHMebHzwXGTqCTtLpoj:6GFlgr4NiGmEGZ+ZV5L0pDEXUNtLpoj - TLSH:
T15E329FF35467EC487B8B6F476EA61264A15BD7882133A77015D83AACC87C6BC7F10920 - Submitted as: datanegujakowavul.pdf
- File type: pdf · Size: 46322 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=celtics+schedule+2019+pdf, https://uploads.strikinglycdn.com/files/30b021cb-bcd5-4e98-b92b-9b249da3739e/34920150316.pdf, https://uploads.strikinglycdn.com/files/ae67afb5-e318-42c4-a5d7-e72fe678f571/41237781473.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=celtics+schedule+2019+pdf
- https://uploads.strikinglycdn.com/files/30b021cb-bcd5-4e98-b92b-9b249da3739e/34920150316.pdf
- https://uploads.strikinglycdn.com/files/ae67afb5-e318-42c4-a5d7-e72fe678f571/41237781473.pdf
- https://uploads.strikinglycdn.com/files/75bf3495-abc1-4861-af60-c009d1ffe09e/maxiladutobar.pdf
- https://uploads.strikinglycdn.com/files/ab20bca4-9fd2-4e01-b639-198a16ccc5b2/70127480189.pdf
- http://seronawu.m2students.net/uploads/1/3/2/8/132815110/rugejeduneweku.pdf
- http://pomewuzo.communitylegalimpact.org/uploads/1/3/1/4/131406390/3bd15b.pdf
- http://files.psychicmediumjudilynch.com/uploads/1/3/1/4/131437924/2148894.pdf
- http://sibemuvax.aliromanow.com/uploads/1/3/1/3/131379421/e692101a.pdf
- https://site-1037283.mozfiles.com/files/1037283/kimowezebogojuxumigit.pdf
- https://site-1036745.mozfiles.com/files/1036745/90200519338.pdf
- https://site-1036692.mozfiles.com/files/1036692/14627084882.pdf
- https://site-1036917.mozfiles.com/files/1036917/72850115240.pdf
- https://site-1036692.mozfiles.com/files/1036692/67429741659.pdf
- https://uploads.strikinglycdn.com/files/b43af458-68ed-4d31-a244-391ed4cc47ba/newozat.pdf
- https://uploads.strikinglycdn.com/files/60563a3d-cc3c-48fb-b5b1-defb09614c83/xozasizisebojejeka.pdf
- https://uploads.strikinglycdn.com/files/102ffe62-27aa-45c1-873a-4194d95a8f17/69668195729.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- seronawu.m2students.net
- pomewuzo.communitylegalimpact.org
- files.psychicmediumjudilynch.com
- sibemuvax.aliromanow.com
- site-1037283.mozfiles.com
- site-1036745.mozfiles.com
- site-1036692.mozfiles.com
- site-1036917.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report