SUSPICIOUS — 41215534313.pdf
SUSPICIOUS — 41215534313.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
0674f3fd95a17614092e7148ee44e71d04cbe1a794a3f00446dfb9f6e690a0bd - SHA-1:
64726a094a78b8a22b865d89ce4b7dc4e6e5d601 - MD5:
56e8ff7c67a5405887ee3962c6c89a99 - ssdeep:
1536:QGFRp46UIPxenBpY5vwe4Xd1W04Aewe6c:dFRpGI/REt1WVwO - TLSH:
T11C33BFF35567ED8CBA82E7876DA62484A145D3887122E3205C8C372ED4BC7BDAF14D60 - Submitted as: 41215534313.pdf
- File type: pdf · Size: 49358 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=canticle+of+the+sun+pdf, https://site-1048550.mozfiles.com/files/1048550/7636497972.pdf, https://site-1038849.mozfiles.com/files/1038849/sezexixuwowazogasonisifaf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=canticle+of+the+sun+pdf
- https://site-1048550.mozfiles.com/files/1048550/7636497972.pdf
- https://site-1038849.mozfiles.com/files/1038849/sezexixuwowazogasonisifaf.pdf
- https://site-1039341.mozfiles.com/files/1039341/kujitozogozasenexotoba.pdf
- https://site-1037241.mozfiles.com/files/1037241/27122709667.pdf
- https://uploads.strikinglycdn.com/files/8fd46030-0e08-43ea-b08d-dd022e400b62/22724931721.pdf
- https://uploads.strikinglycdn.com/files/5bb661a0-5cf9-4355-809e-71b7b0e87560/nasifirisetemigi.pdf
- https://uploads.strikinglycdn.com/files/a439997d-2a6f-464b-9f4c-a5ef740cb10c/vezekibubakolotozij.pdf
- https://uploads.strikinglycdn.com/files/1a937d33-8d82-4cb8-9600-017b34b79e2f/birudomojepoleve.pdf
- https://uploads.strikinglycdn.com/files/0dca64cf-6b4e-4871-b55e-acd49e77eb68/lebasumevewutibamadozot.pdf
- https://uploads.strikinglycdn.com/files/17abf298-6d1e-4488-8040-85a9a8fe3041/25548858864.pdf
- https://uploads.strikinglycdn.com/files/c7355472-d99a-4880-8160-96bb2006a551/40666038782.pdf
- https://uploads.strikinglycdn.com/files/21f33d15-58f2-4def-b91c-30eb10c542d3/23158337497.pdf
- https://uploads.strikinglycdn.com/files/c33a0dfc-26d0-4345-b17a-149570ef6583/dudijotowutezoxagid.pdf
- https://uploads.strikinglycdn.com/files/bc0ba259-4d05-4a66-b76d-6d9715a6ad3a/24195791149.pdf
- https://uploads.strikinglycdn.com/files/32cb155d-bf88-4a2b-9a44-727c43c77c92/bubodos.pdf
- https://uploads.strikinglycdn.com/files/5b8a0136-cbdf-4f46-ba3f-2e9e3e4b6e10/70689676245.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1048550.mozfiles.com
- site-1038849.mozfiles.com
- site-1039341.mozfiles.com
- site-1037241.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report