SUSPICIOUS — 71093066245.pdf
SUSPICIOUS — 71093066245.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
fd6442af8f8b0bc8e1120cf540b7ddd65a80f34ba4a08c3ea4e0c75e416c6ad8 - SHA-1:
f2ef859af85b549527e119a3a230b12713a2e8ff - MD5:
7b8799f7ad87fbdcff0d1d5e2ece8736 - ssdeep:
768:cgGzpDcG3OK4YpFaEgYH+g9JrT0Z/519n3AdNd:5GF4Gg2+gHEd519nQdNd - TLSH:
T14F319EF360A7DE8D2987DF43BDEB159EA089D6882122D36041D8726CC4BC6BD6F11950 - Submitted as: 71093066245.pdf
- File type: pdf · Size: 40867 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=siyasi+tarih+r%25C4%25B1fat+u%25C3%25A7arol, http://xofivumu.spinnerdavetipstactics.com/uploads/1/3/1/6/131637308/7503808.pdf, http://files.dohalands.net/uploads/1/3/1/4/131437464/sedobaj-mugepuxosonova.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=siyasi+tarih+r%25C4%25B1fat+u%25C3%25A7arol
- http://xofivumu.spinnerdavetipstactics.com/uploads/1/3/1/6/131637308/7503808.pdf
- http://files.dohalands.net/uploads/1/3/1/4/131437464/sedobaj-mugepuxosonova.pdf
- http://files.wilsonboosterclub.com/uploads/1/3/1/3/131379434/7752964.pdf
- https://cdn.shopify.com/s/files/1/0484/9667/2930/files/16195132620.pdf
- https://cdn.shopify.com/s/files/1/0482/8145/2706/files/lelouch_and_cc_wallpaper.pdf
- https://cdn.shopify.com/s/files/1/0436/9039/3755/files/you_look_like_a_movie_song_lyrics.pdf
- https://cdn.shopify.com/s/files/1/0483/6009/5895/files/74331002155.pdf
- https://cdn.shopify.com/s/files/1/0433/9479/3635/files/who_owns_in_motion_fitness_chico.pdf
- http://files.bpoelks411.org/uploads/1/3/0/8/130813818/leburugipejemub.pdf
- http://files.brighterdaylivin.com/uploads/1/3/1/3/131378950/fomukufelarobogomone.pdf
- http://files.jessicayeermt.com/uploads/1/3/1/3/131379035/kiwumer-xawijumenis-dufeziti-porutedokiva.pdf
- http://files.lacofc.org/uploads/1/3/0/8/130813427/rulepod.pdf
- http://suvol.bottlealleytheatre.com/uploads/1/3/1/1/131163763/rosesozoku-nutigasivipufip-gizatopu-pibibibavupe.pdf
- http://files.superawesomevolleyball.com/uploads/1/3/1/6/131636990/8208886.pdf
- http://files.pautauwakfarms.com/uploads/1/3/1/3/131380915/6150933.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- xofivumu.spinnerdavetipstactics.com
- files.dohalands.net
- files.wilsonboosterclub.com
- cdn.shopify.com
- files.bpoelks411.org
- files.brighterdaylivin.com
- files.jessicayeermt.com
- files.lacofc.org
- suvol.bottlealleytheatre.com
- files.superawesomevolleyball.com
- files.pautauwakfarms.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report