SUSPICIOUS — 12418139501.pdf
SUSPICIOUS — 12418139501.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
ed20c136a0115e36cc2e039a880a92b1f4a140a381729f583a48163345e8df71 - SHA-1:
feab2d4607a3118769d1cfedbfd428f3977a521a - MD5:
111f591c14d6830a5f255c28a0e34e47 - ssdeep:
768:5gGzpD/i99eBbv1KdWeQWac5AbGLnwGLljPkF:6GFLRBJ2FNh6b8tNPkF - TLSH:
T1D0308DF7919BED8C7AC6AB47AEE60055318AC788713392A05598337DC4BC6FC7E10960 - Submitted as: 12418139501.pdf
- File type: pdf · Size: 36180 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=oakland+military+institute, https://site-1039446.mozfiles.com/files/1039446/vovafobedovozonaxonabafol.pdf, https://site-1039740.mozfiles.com/files/1039740/vuzobajoxoweforukedo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=oakland+military+institute
- https://site-1039446.mozfiles.com/files/1039446/vovafobedovozonaxonabafol.pdf
- https://site-1039740.mozfiles.com/files/1039740/vuzobajoxoweforukedo.pdf
- https://site-1042349.mozfiles.com/files/1042349/58289532991.pdf
- https://site-1042917.mozfiles.com/files/1042917/42882482012.pdf
- https://site-1037143.mozfiles.com/files/1037143/16642124028.pdf
- https://site-1037824.mozfiles.com/files/1037824/pogogu.pdf
- https://site-1037029.mozfiles.com/files/1037029/48103334807.pdf
- https://uploads.strikinglycdn.com/files/cba79cb7-3de3-4af5-aaff-f011e62c733d/8906233237.pdf
- https://uploads.strikinglycdn.com/files/cf7647d5-6e63-44b0-9c50-50132d6b358a/77647410453.pdf
- https://uploads.strikinglycdn.com/files/00f63dcd-d8a9-431b-9de3-4f53c3c9f1dc/867799339.pdf
- https://uploads.strikinglycdn.com/files/dc2106b2-b5e9-4dd9-b395-2341ec6194a5/wesilu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1039446.mozfiles.com
- site-1039740.mozfiles.com
- site-1042349.mozfiles.com
- site-1042917.mozfiles.com
- site-1037143.mozfiles.com
- site-1037824.mozfiles.com
- site-1037029.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report