SUSPICIOUS — gelezesefosekozatexodu.pdf
SUSPICIOUS — gelezesefosekozatexodu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
a5164c650ae4ab87528d0726e902138500565737cb083e0be32ec9166df385c0 - SHA-1:
124d3e49b4f770d15ff78fb5ac700a0a5c2fc364 - MD5:
a548b1584dfdfe17ae69bcca5a2175f6 - ssdeep:
768:mgGzpDarm1d4y/e7++mFJDFPeNQdX3hY2Q3TFkwDqQOEi7SdWtSW07R:zGFGiF5+mFJpPeeNhY2MduEiOktH0R - TLSH:
T167329EF751A7ED9C7A4AAB03A9E30495604AC74D607297A009CC3B6DC5BCAFD3E40A14 - Submitted as: gelezesefosekozatexodu.pdf
- File type: pdf · Size: 44710 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=types+of+kitesurfing, https://site-1041861.mozfiles.com/files/1041861/38885268278.pdf, https://site-1039547.mozfiles.com/files/1039547/83747338706.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=types+of+kitesurfing
- https://site-1041861.mozfiles.com/files/1041861/38885268278.pdf
- https://site-1039547.mozfiles.com/files/1039547/83747338706.pdf
- https://site-1041181.mozfiles.com/files/1041181/20347153134.pdf
- https://site-1039510.mozfiles.com/files/1039510/89056032605.pdf
- https://site-1043803.mozfiles.com/files/1043803/44402558382.pdf
- https://uploads.strikinglycdn.com/files/d238ede5-5df8-497b-870d-d16b84a846e8/94222269379.pdf
- https://uploads.strikinglycdn.com/files/ce61e730-fb3e-4951-8046-32c73968d838/pozonos.pdf
- https://uploads.strikinglycdn.com/files/b43506e0-2506-4605-801f-3d57b953777c/57577515372.pdf
- http://files.bobminney.com/uploads/1/3/1/3/131379306/5436184.pdf
- http://zobajat.artstudiosanneke.com/uploads/1/3/2/6/132681300/9e33d94785e.pdf
- http://wenezi.german-teacher-online.com/uploads/1/3/2/7/132740815/9c5cb.pdf
- http://files.thecatalystgames.com/uploads/1/3/1/4/131453560/cf2f8b7.pdf
- https://uploads.strikinglycdn.com/files/9f68057b-e87d-445c-a550-32752e617db7/62511368548.pdf
- https://uploads.strikinglycdn.com/files/83c8a0e4-fdd3-4c7d-99ac-c1985bbc9268/zepewabajupala.pdf
- https://uploads.strikinglycdn.com/files/2df15276-8c22-4d0f-9ca7-9dbf47803d76/papoxevitixoromupuse.pdf
- https://uploads.strikinglycdn.com/files/538e688d-d449-4588-ae52-a93ae1735a0d/28496932148.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1041861.mozfiles.com
- site-1039547.mozfiles.com
- site-1041181.mozfiles.com
- site-1039510.mozfiles.com
- site-1043803.mozfiles.com
- uploads.strikinglycdn.com
- files.bobminney.com
- zobajat.artstudiosanneke.com
- wenezi.german-teacher-online.com
- files.thecatalystgames.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report