SUSPICIOUS — 27378359123.pdf
SUSPICIOUS — 27378359123.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
1066b9585db7352ca034a8c2de6b1777da142b942a53845d5dd7f0d5035358ff - SHA-1:
b2a415a81c487658b6e3cbf9e8657761be6d3b8b - MD5:
77c9547f6325b1060c4ae9424c946321 - ssdeep:
768:QgGzpDkb6Ms/vXKDrdJPDxc8Zp+nvwwA7cFDG1gL5dW4daocQF3B3P:9GFQGKXdJNVZpQwxuggL5Hda/QF3xP - TLSH:
T1C7319EF31097EC8C368EAB076EFB01996146D2C96136E7A069CC676D907C2ED6F00D61 - Submitted as: 27378359123.pdf
- File type: pdf · Size: 42084 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=bible+riddles+with+answers+pdf, https://uploads.strikinglycdn.com/files/a14cd14b-5473-4532-a150-52a12e2c941a/82444701130.pdf, https://uploads.strikinglycdn.com/files/904df8d7-2bb1-457f-bdf5-c82fe19268e5/54344111935.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=bible+riddles+with+answers+pdf
- https://uploads.strikinglycdn.com/files/a14cd14b-5473-4532-a150-52a12e2c941a/82444701130.pdf
- https://uploads.strikinglycdn.com/files/904df8d7-2bb1-457f-bdf5-c82fe19268e5/54344111935.pdf
- https://uploads.strikinglycdn.com/files/922e7d4a-7ed8-4a3c-9848-f65aaf0db5bb/95812445489.pdf
- https://uploads.strikinglycdn.com/files/dc73e1bb-3bbf-4b15-a04c-459b7ef4547f/vowuzo.pdf
- https://uploads.strikinglycdn.com/files/90bb43ed-864a-458d-b8ea-b8d862971a01/fuwavolasusasapepulosezux.pdf
- https://uploads.strikinglycdn.com/files/b2144c74-7f98-4d06-aae4-c1f2201150d0/40490108241.pdf
- http://rigib.septembershowcasesale.com/uploads/1/3/0/7/130775443/be265437fbd.pdf
- http://zatofiv.intothewildinc.org/uploads/1/3/0/8/130874524/6065022.pdf
- http://nupelob.sunriseonlinenews.com/uploads/1/3/0/7/130775683/wivevujirupax-jipapabixivel-forusogi.pdf
- http://files.petitesweetshouse.com/uploads/1/3/1/8/131856290/9988602.pdf
- http://files.civil-engineering-architecture.com/uploads/1/3/2/6/132695363/181272.pdf
- https://cdn.shopify.com/s/files/1/0434/3765/4178/files/service_level_agreement_india.pdf
- https://cdn.shopify.com/s/files/1/0438/2310/4160/files/46045409819.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- rigib.septembershowcasesale.com
- zatofiv.intothewildinc.org
- nupelob.sunriseonlinenews.com
- files.petitesweetshouse.com
- files.civil-engineering-architecture.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report