SUSPICIOUS — que_es_situacion_comunicativa.pdf
SUSPICIOUS — que_es_situacion_comunicativa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
1670d0d8c9d41be360659496bad95332facee795fd18520596062dc65591af0e - SHA-1:
2140cfe6dca6f0f1eb859dacfce518b7e53b854e - MD5:
bc5a799c4389e978ecbf4cf98e8d9246 - ssdeep:
768:LgGzpDZpLoaAs0yZ9rEerylmc91vrBlAu+XeV9Z4c2FTtTkkuWPMXM/OQUwrmmO3:0GF1pLoOB9rEf21dkkukMXMzUwioDmnh - TLSH:
T188328DF750A7ED4C3EC79B836EBA12595449D748A132EBA4448C6B2CC47C2BDBF10A50 - Submitted as: que_es_situacion_comunicativa.pdf
- File type: pdf · Size: 46517 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=que+es+situacion+comunicativa, https://cdn-cms.f-static.net/uploads/4381105/normal_5f8d7fc55924c.pdf, https://cdn-cms.f-static.net/uploads/4366652/normal_5f8725f8ed5a0.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=que+es+situacion+comunicativa
- https://cdn-cms.f-static.net/uploads/4381105/normal_5f8d7fc55924c.pdf
- https://cdn-cms.f-static.net/uploads/4366652/normal_5f8725f8ed5a0.pdf
- https://cdn-cms.f-static.net/uploads/4369928/normal_5f883ce295f9f.pdf
- https://cdn-cms.f-static.net/uploads/4382190/normal_5f9085282efcb.pdf
- https://uploads.strikinglycdn.com/files/8037dae7-bc78-4231-a56a-1beb36174fe3/1999_ford_f250_parts.pdf
- https://uploads.strikinglycdn.com/files/83a029f5-a991-4189-baf2-674fdefafa2d/13434633678.pdf
- https://uploads.strikinglycdn.com/files/491a8253-892c-4f97-9668-9187ff0efd92/rodogirekejo.pdf
- https://uploads.strikinglycdn.com/files/294f3560-b9c8-46cc-8ec0-941fbb47913d/rifejir.pdf
- https://uploads.strikinglycdn.com/files/aeefff11-1be7-4bd8-ac39-90e96ae71cec/riwud.pdf
- https://cdn.shopify.com/s/files/1/0435/8681/4109/files/80642707233.pdf
- https://cdn.shopify.com/s/files/1/0438/2212/1122/files/6748091417.pdf
- https://cdn.shopify.com/s/files/1/0434/2117/1879/files/7066190865.pdf
- https://cdn.shopify.com/s/files/1/0434/6730/9206/files/14642154256.pdf
- https://cdn.shopify.com/s/files/1/0434/0586/9208/files/zofapeberejirexawur.pdf
- https://cdn-cms.f-static.net/uploads/4366057/normal_5f876b546335e.pdf
- https://cdn-cms.f-static.net/uploads/4387715/normal_5f905ab91899e.pdf
- https://cdn-cms.f-static.net/uploads/4373986/normal_5f8a5300709c9.pdf
- https://cdn-cms.f-static.net/uploads/4366666/normal_5f8aa893d0a6f.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/1a27643b41869.pdf
- https://vabeliguteziji.weebly.com/uploads/1/3/1/3/131379360/bibonomexalevi.pdf
- https://cdn.shopify.com/s/files/1/0484/4784/8602/files/4140320268.pdf
- https://cdn.shopify.com/s/files/1/0266/8793/0561/files/82697450522.pdf
- https://cdn.shopify.com/s/files/1/0480/7481/7693/files/zifemulav.pdf
- https://cdn.shopify.com/s/files/1/0438/6501/4432/files/xenusal.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- zoxuzuxebexot.weebly.com
- vabeliguteziji.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report