SUSPICIOUS — nizitokizad.pdf
SUSPICIOUS — nizitokizad.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
f6b34c671ea947e224b4edd9c65894550420e90c08821b0af8b42e76064169c4 - SHA-1:
7884af30160008915c0106b2efa4e874ee4e7e73 - MD5:
70214bdf6f11c3413c8474f31d7cf8f1 - ssdeep:
1536:qGFG+hLcXu7pPbYZyufDnFsfYL/MIcW27J2aJCQDa:TFG+htpzIyMHL/MIK2aJq - TLSH:
T12E349EF31167CDCCBAC7AB83ADF610985586C68C3132976055987AACD97C6FCAF10A10 - Submitted as: nizitokizad.pdf
- File type: pdf · Size: 55435 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=ejercicios+lateralidad+cruzada+pdf, https://uploads.strikinglycdn.com/files/87fbbdcd-0222-46c2-aa9a-8e4c4cc75b0d/wabidukomagete.pdf, https://uploads.strikinglycdn.com/files/72fee973-e82b-4d5f-aeea-5cec6b4f797f/11547930287.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=ejercicios+lateralidad+cruzada+pdf
- https://uploads.strikinglycdn.com/files/87fbbdcd-0222-46c2-aa9a-8e4c4cc75b0d/wabidukomagete.pdf
- https://uploads.strikinglycdn.com/files/72fee973-e82b-4d5f-aeea-5cec6b4f797f/11547930287.pdf
- https://uploads.strikinglycdn.com/files/c115f416-acb3-448d-8ebb-5984d2117b67/dekoxutenadinopane.pdf
- https://uploads.strikinglycdn.com/files/fa9a523d-bf29-4d3b-9269-9213bc1b5bb3/ruviwuzijalenuje.pdf
- https://site-1038827.mozfiles.com/files/1038827/30784282271.pdf
- https://site-1037149.mozfiles.com/files/1037149/nukidokabop.pdf
- https://site-1038810.mozfiles.com/files/1038810/15680441138.pdf
- https://site-1036791.mozfiles.com/files/1036791/64746480051.pdf
- https://site-1036873.mozfiles.com/files/1036873/fajite.pdf
- https://site-1036909.mozfiles.com/files/1036909/fadeweliterodomimopej.pdf
- https://site-1037864.mozfiles.com/files/1037864/warekuput.pdf
- https://site-1037094.mozfiles.com/files/1037094/mofufejebogegozulife.pdf
- https://site-1037091.mozfiles.com/files/1037091/witebeluwew.pdf
- https://site-1036629.mozfiles.com/files/1036629/favexofiboxako.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1038827.mozfiles.com
- site-1037149.mozfiles.com
- site-1038810.mozfiles.com
- site-1036791.mozfiles.com
- site-1036873.mozfiles.com
- site-1036909.mozfiles.com
- site-1037864.mozfiles.com
- site-1037094.mozfiles.com
- site-1037091.mozfiles.com
- site-1036629.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report