SUSPICIOUS — 78620325620.pdf
SUSPICIOUS — 78620325620.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
046d6c338ad6263821a03474e9490a661534856676a266f9768a1b4caef35992 - SHA-1:
ad182b3406b050f42cd6ed8f9a6c043492013ef5 - MD5:
cf96ec0000f4c0274bb170f4afd6272b - ssdeep:
1536:cGFVOB5YCxHGO40p4Ar4+IVl81/r/VMcN+mUXg9UNbWW8r0NNaqz3d:5FVODtx40p404+InqRRUXYybnNIqx - TLSH:
T16636CFB32047ED8C268AEB076DFA044C6546C74C6132A7A049C8773CDA7CAEC7E65951 - Submitted as: 78620325620.pdf
- File type: pdf · Size: 67666 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=neko+atsume+cheats+cat+guide, https://uploads.strikinglycdn.com/files/e1ab09e9-5e11-4a3f-830f-1b009184392b/xurafogizepesajeb.pdf, https://uploads.strikinglycdn.com/files/b2c8bacf-fd5a-4239-b5da-fdfabbe0f3b6/senosotanedaxuvukunipe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=neko+atsume+cheats+cat+guide
- https://uploads.strikinglycdn.com/files/e1ab09e9-5e11-4a3f-830f-1b009184392b/xurafogizepesajeb.pdf
- https://uploads.strikinglycdn.com/files/b2c8bacf-fd5a-4239-b5da-fdfabbe0f3b6/senosotanedaxuvukunipe.pdf
- https://uploads.strikinglycdn.com/files/8d422107-742c-4491-b54d-aac85f3adfc4/pujojadipasevumemawem.pdf
- https://uploads.strikinglycdn.com/files/4a3f38fe-f8a5-4469-9f7a-d024e3ef44f6/xedogopokivu.pdf
- https://cdn.shopify.com/s/files/1/0497/2013/1745/files/44261052141.pdf
- https://cdn.shopify.com/s/files/1/0437/8155/4325/files/jojupovomixewapubufovag.pdf
- https://cdn.shopify.com/s/files/1/0437/4410/0506/files/merit_system_definition_us_government.pdf
- https://cdn.shopify.com/s/files/1/0434/2120/4631/files/jiwerokidakez.pdf
- https://cdn.shopify.com/s/files/1/0434/3437/7377/files/80337104861.pdf
- http://files.ianlaidlawlcsw.com/uploads/1/3/2/8/132814007/e92e5f143a111.pdf
- http://wijen.mao-bo.com/uploads/1/3/1/4/131437308/31fa4e89926c.pdf
- http://files.vk3sn.net/uploads/1/3/1/8/131871894/d40f274a4b81b4.pdf
- http://files.gogreenparkridge.org/uploads/1/3/0/8/130814861/9c52553.pdf
- https://uploads.strikinglycdn.com/files/85107099-7702-426e-b62e-ff069abb9e1e/99400940331.pdf
- https://uploads.strikinglycdn.com/files/e9166774-5913-47ef-8b5d-bfc067f3c035/saxalabon.pdf
- https://uploads.strikinglycdn.com/files/da28d541-7758-4979-b619-376d73b26b4b/zazibelinizefugiriwixu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- files.ianlaidlawlcsw.com
- wijen.mao-bo.com
- files.vk3sn.net
- files.gogreenparkridge.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report