SUSPICIOUS — 89425044106.pdf
SUSPICIOUS — 89425044106.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
03f6d034f6ebe1e9032062a80be6fcdea0e26b852f225a7230b005b9dacc3c9b - SHA-1:
ed2fe70bc53dda042df403de0986e5428e379ca8 - MD5:
64a81a51fea77b0fbd5e531a43dc7984 - ssdeep:
1536:KGFQpDTIK2T/X8HA0szoz35J3j5L589JfHWbAb+x7:zFQpDo70pModJ3j5VOJfQQs - TLSH:
T10F36BEF310A7DD4C368B5B87A9F714A4B986D7842237AAA0058C6B2CC47C7FD6F20651 - Submitted as: 89425044106.pdf
- File type: pdf · Size: 64017 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=arap%25C3%25A7a+soy+a%25C4%259Fac%25C4%25B1+%25C3%25B6rnekleri, http://juwiko.thesudsygoatbathco.com/uploads/1/3/0/7/130776485/wutirakijoj_duwelamolunet_kidewotata.pdf, http://files.rschorus.com/uploads/1/3/0/8/130814342/8213499.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=arap%25C3%25A7a+soy+a%25C4%259Fac%25C4%25B1+%25C3%25B6rnekleri
- http://juwiko.thesudsygoatbathco.com/uploads/1/3/0/7/130776485/wutirakijoj_duwelamolunet_kidewotata.pdf
- http://files.rschorus.com/uploads/1/3/0/8/130814342/8213499.pdf
- http://files.approachapparel.com/uploads/1/3/1/3/131383664/8009279.pdf
- http://files.careerhighschool.org/uploads/1/3/1/3/131383373/1302130.pdf
- http://files.capturedsuductionphotography.com/uploads/1/3/0/7/130738824/sajitadinud-kokopijod-tiledideze-burileferobafev.pdf
- http://files.palaceofcuriosities.com/uploads/1/3/0/7/130776420/9295211.pdf
- http://files.happylivingg.com/uploads/1/3/1/3/131398099/5906988.pdf
- http://files.aquariusredang.com/uploads/1/3/2/8/132814544/relonile_nazesujik.pdf
- https://uploads.strikinglycdn.com/files/46bd6629-a14e-4d94-a79f-b4352ead3a58/fevazatepulumijobik.pdf
- https://uploads.strikinglycdn.com/files/f6560008-ea28-40bc-abe6-0d9dac99e27b/69351331344.pdf
- https://uploads.strikinglycdn.com/files/83c06ab8-3ae5-40f0-a5ef-df583976ffea/nufarobinelaxuwibivobo.pdf
- https://uploads.strikinglycdn.com/files/3023b6ee-d1fc-4965-8bc1-4fbb4fd283d5/migelobosopusuposofip.pdf
- https://uploads.strikinglycdn.com/files/318bcbce-776d-4cef-b94f-5dbee54ca795/29286357071.pdf
- https://site-1038728.mozfiles.com/files/1038728/posafofemuv.pdf
- https://site-1039235.mozfiles.com/files/1039235/51915945673.pdf
- https://site-1039688.mozfiles.com/files/1039688/pagenepojozagoxa.pdf
- https://site-1041485.mozfiles.com/files/1041485/jupogufulizovesawujegibi.pdf
- https://site-1042539.mozfiles.com/files/1042539/dujuzoxijezutabot.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- juwiko.thesudsygoatbathco.com
- files.rschorus.com
- files.approachapparel.com
- files.careerhighschool.org
- files.capturedsuductionphotography.com
- files.palaceofcuriosities.com
- files.happylivingg.com
- files.aquariusredang.com
- uploads.strikinglycdn.com
- site-1038728.mozfiles.com
- site-1039235.mozfiles.com
- site-1039688.mozfiles.com
- site-1041485.mozfiles.com
- site-1042539.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report