SUSPICIOUS — vozoriniremekanizatoga.pdf
SUSPICIOUS — vozoriniremekanizatoga.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
a9f3aec4f19470d4b801b792efa49b67d400413f00cdf0b9553c23bf9a2bdc7a - SHA-1:
ab50bcc301dcb12a650f5bcc69551fe1bfd7a315 - MD5:
32c9df686981c317c1bb0cac1beb5178 - ssdeep:
1536:TGFJ2OG/0obOKC2TZRViz9jk0J4fcISmOV2CUG:iFJtO0obOORkz9YOhVF - TLSH:
T1A236CFF310A7DC4CB9876F036EE52459624AD288A13293B418C8776EC47C3FE7DA1960 - Submitted as: vozoriniremekanizatoga.pdf
- File type: pdf · Size: 66561 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=werewolves+game+cards+pdf, https://site-1037869.mozfiles.com/files/1037869/fokogavet.pdf, https://site-1037035.mozfiles.com/files/1037035/98118193511.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=werewolves+game+cards+pdf
- https://site-1037869.mozfiles.com/files/1037869/fokogavet.pdf
- https://site-1037035.mozfiles.com/files/1037035/98118193511.pdf
- https://site-1036972.mozfiles.com/files/1036972/96253569402.pdf
- https://site-1037085.mozfiles.com/files/1037085/60907082635.pdf
- https://uploads.strikinglycdn.com/files/23313e43-ea75-4d3a-b174-1e6d160d7c9f/vegovopagi.pdf
- https://uploads.strikinglycdn.com/files/a6027ed2-e7e8-4788-b1b9-3f50c57471c8/vojogit.pdf
- https://uploads.strikinglycdn.com/files/1fa085ff-8baf-4325-933c-ec868f84214e/dutofikubafi.pdf
- https://uploads.strikinglycdn.com/files/cd79d2f4-e918-41cf-9258-c5246e5efc99/6893053465.pdf
- https://uploads.strikinglycdn.com/files/a5dfb193-7e65-4e70-9f74-ad038c64a2ad/mawalelejowabiro.pdf
- https://uploads.strikinglycdn.com/files/2735c4f3-ab19-4121-b89d-4ba6af18a0a0/64183578897.pdf
- https://uploads.strikinglycdn.com/files/43d8e216-f025-4714-97d0-7ab7c742ee88/33008106120.pdf
- http://kavigeb.shaikheskander.com/uploads/1/3/1/1/131164456/sevumorarepop.pdf
- http://files.parkavere.com/uploads/1/3/1/0/131070001/virusax_saligotifekuju_lurutepeki.pdf
- http://files.ketubahbykarny.com/uploads/1/3/2/6/132681342/jiraneluverupizi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1037869.mozfiles.com
- site-1037035.mozfiles.com
- site-1036972.mozfiles.com
- site-1037085.mozfiles.com
- uploads.strikinglycdn.com
- kavigeb.shaikheskander.com
- files.parkavere.com
- files.ketubahbykarny.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report