SUSPICIOUS — 72352108607.pdf
SUSPICIOUS — 72352108607.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
e0f189f4a556c033cd5fc39a6fefd39ae56a6df3a29af633166c0c8538566c6a - SHA-1:
4af52d52f9b80d436b07196da7a3b006287839f0 - MD5:
a62880f9ada217f0d1a16828b6a37863 - ssdeep:
768:5gGzpDZDem0HcGPcLUkYhnc8o/xGptACfcqguzx9KM7MY8H2GSPVDNp:6GFVDeWuWwpfSy7Pp/PVDNp - TLSH:
T17833BEF750ABED8C7A865743BDF30494508AE2C8613387A058ED7B2CC4BC5BDAE10961 - Submitted as: 72352108607.pdf
- File type: pdf · Size: 49216 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=article+writing+format+cbse+class+10th, https://site-1037241.mozfiles.com/files/1037241/59299329364.pdf, https://site-1036848.mozfiles.com/files/1036848/vazase.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=article+writing+format+cbse+class+10th
- https://site-1037241.mozfiles.com/files/1037241/59299329364.pdf
- https://site-1036848.mozfiles.com/files/1036848/vazase.pdf
- https://site-1038412.mozfiles.com/files/1038412/tubowitakikoliwutikete.pdf
- https://site-1036923.mozfiles.com/files/1036923/noxujokajev.pdf
- https://uploads.strikinglycdn.com/files/98327209-448e-49e2-9e4f-150b1e38fb27/19243654669.pdf
- https://uploads.strikinglycdn.com/files/e3cf6431-a504-4f46-a2a4-ff7935bd7f4e/dizefef.pdf
- https://uploads.strikinglycdn.com/files/98367cef-5509-4853-a41e-4a2e982cb759/13423550224.pdf
- http://files.sidneyberthier.com/uploads/1/3/2/7/132740694/sewesanofisalogofato.pdf
- http://balokix.whydohorses.com/uploads/1/3/2/6/132682859/9712286.pdf
- http://files.lizsowersburas.com/uploads/1/3/2/7/132741593/wanovapogopul_jujuwoma_fipamunibexex.pdf
- http://xudelupaw.yuanmodellinggroup.com/uploads/1/3/0/7/130775432/5204074.pdf
- https://uploads.strikinglycdn.com/files/eb8a6e28-4f59-4041-8061-63dc8b47f7f7/95998980868.pdf
- https://uploads.strikinglycdn.com/files/2574025e-79cc-40c9-850b-6d44e14b9620/notujelijidina.pdf
- https://uploads.strikinglycdn.com/files/1423a002-51a7-4e85-9434-da6028fca554/bizexixolizibogeji.pdf
- https://uploads.strikinglycdn.com/files/131119a8-b08c-4111-ae32-bc35d07883f7/bamodupujuviwifofeso.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1037241.mozfiles.com
- site-1036848.mozfiles.com
- site-1038412.mozfiles.com
- site-1036923.mozfiles.com
- uploads.strikinglycdn.com
- files.sidneyberthier.com
- balokix.whydohorses.com
- files.lizsowersburas.com
- xudelupaw.yuanmodellinggroup.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report