SUSPICIOUS — lokunofopafoz.pdf
SUSPICIOUS — lokunofopafoz.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
ade0a495638058ab1b074c782a3fd1326b55f249570687e1d37e250131869b6b - SHA-1:
d5d69d76a2449757d1300b5a01cbab9a20a95c3b - MD5:
f935a86389ba845fc0d71fa1c7318ae3 - ssdeep:
768:cgGzpDQWs7nhn3xBEotsNhu8pev/YsVR7m+wzNdsAiLP2FBd:5GFkT7BWNUKCRjwzbsAiL+FBd - TLSH:
T152318DF32067ED8C3AC7DF436EAA285A9149D64D6173977058C87B6CC4BC2AC6F00925 - Submitted as: lokunofopafoz.pdf
- File type: pdf · Size: 42776 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=betaflight+f4+manual+pdf, https://uploads.strikinglycdn.com/files/e127bb83-66eb-47d9-8059-6183af9e95ae/84137232938.pdf, https://uploads.strikinglycdn.com/files/0b4f254e-327a-46e5-9b31-a96beac199d6/jepejudipudulebuzitapa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=betaflight+f4+manual+pdf
- https://uploads.strikinglycdn.com/files/e127bb83-66eb-47d9-8059-6183af9e95ae/84137232938.pdf
- https://uploads.strikinglycdn.com/files/0b4f254e-327a-46e5-9b31-a96beac199d6/jepejudipudulebuzitapa.pdf
- https://uploads.strikinglycdn.com/files/0178ca12-7f18-430d-ae3e-357531ea777d/38447412097.pdf
- http://files.termaxe.com/uploads/1/3/1/8/131872079/bebivu.pdf
- http://dawazi.3handstephen.com/uploads/1/3/0/9/130969280/b71c931a.pdf
- http://mokeju.eartharkbotswana.com/uploads/1/3/1/4/131483245/5513673.pdf
- http://files.aandwtransport.com/uploads/1/3/1/4/131452938/1dff415ba5b521.pdf
- http://tajaso.rivertonhighmusic.com/uploads/1/3/0/7/130740393/jujufogitab.pdf
- http://nilezuzul.nasarioremembers.com/uploads/1/3/0/7/130775598/jinemuduja-modivalova.pdf
- http://files.rebelliousrheaboutique.shop/uploads/1/3/1/4/131406413/2090860.pdf
- http://files.yourfavoritept.com/uploads/1/3/1/4/131483520/tezofele-beraro-popuwemuvinin.pdf
- http://risotim.spartanburgscottishrite.com/uploads/1/3/0/9/130969754/58809ac.pdf
- http://files.ladivina.net/uploads/1/3/0/7/130775413/ca705ede2e8dfa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- files.termaxe.com
- dawazi.3handstephen.com
- mokeju.eartharkbotswana.com
- files.aandwtransport.com
- tajaso.rivertonhighmusic.com
- nilezuzul.nasarioremembers.com
- files.rebelliousrheaboutique.shop
- files.yourfavoritept.com
- risotim.spartanburgscottishrite.com
- files.ladivina.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report