SUSPICIOUS — 52421858420.pdf
SUSPICIOUS — 52421858420.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
123d4bb0e7d3a4320084d3a58560391e73ebacffe66c94100d941771d06fff91 - SHA-1:
249910b83147a4f31871a2802cefa39352e1b975 - MD5:
d0f334f58f04c19f8ad3e46f9bdff88e - ssdeep:
1536:ZGFaaYAulnaQlCFwH/RwznoBCHWevtkmgWMpCl3:sFaaBulVCSH/RWUCjVkm9kCR - TLSH:
T1C334AEF34147DE8DA78BEB07E9AA0459714AD78C612292A0488C7B3DC47C6FDAF11E50 - Submitted as: 52421858420.pdf
- File type: pdf · Size: 55991 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=9th+class+math+notes+in+urdu+pdf, https://uploads.strikinglycdn.com/files/b6caa986-f7d5-4b52-8b12-737a5db9d507/25999858551.pdf, https://uploads.strikinglycdn.com/files/c2eb8245-b1e4-4e58-a1ae-22c661f93e28/kokifajipodawejagubasiz.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=9th+class+math+notes+in+urdu+pdf
- https://uploads.strikinglycdn.com/files/b6caa986-f7d5-4b52-8b12-737a5db9d507/25999858551.pdf
- https://uploads.strikinglycdn.com/files/c2eb8245-b1e4-4e58-a1ae-22c661f93e28/kokifajipodawejagubasiz.pdf
- https://uploads.strikinglycdn.com/files/edaf14a0-5f55-4a42-9f34-433be7f84a77/23343903395.pdf
- https://uploads.strikinglycdn.com/files/73213ab5-c2dc-4a02-8043-dd830f87e8bc/woxakelebiwatorisoxibazaf.pdf
- https://uploads.strikinglycdn.com/files/620c33a4-565b-4062-ae44-25d5a8e42e2f/famumefuzevuzevibosofero.pdf
- https://cdn.shopify.com/s/files/1/0429/0537/0787/files/orange_front_door_colors.pdf
- https://cdn.shopify.com/s/files/1/0457/3783/6710/files/33721079987.pdf
- https://cdn.shopify.com/s/files/1/0438/3748/9309/files/kojunujip.pdf
- https://uploads.strikinglycdn.com/files/905a4c21-839d-41bd-a2f4-49be47c2e343/dijidosi.pdf
- https://uploads.strikinglycdn.com/files/2b79cc72-098e-44c2-afb4-d823a85b8bb6/vozarija.pdf
- https://uploads.strikinglycdn.com/files/e3cc32bb-46e0-4c16-92a1-1572c0b159dc/22533383720.pdf
- https://uploads.strikinglycdn.com/files/b5d3e30d-95ab-4f73-b7cf-f80a099f8f6c/ravadotokulebufaguvoziwem.pdf
- http://files.brtrescue.org/uploads/1/3/2/7/132740743/vexusoreduvokaso.pdf
- http://files.hillhousecollegeadvising.com/uploads/1/3/1/8/131856844/1793798.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- files.brtrescue.org
- files.hillhousecollegeadvising.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report