MALICIOUS — 56163000455.pdf
MALICIOUS — 56163000455.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
197cd5fd5aa56fd06b348f8efbff6bc3586ebaef5bc3766c8aa9b2cad92efff2 - SHA-1:
b9a8d03b1798eaabd1a0760ce70f69bb83b79681 - MD5:
3cdd740025673bd56af66968ee7a0e7b - ssdeep:
768:KgGzpDJjUiQ1ckAUoK0n88RBAjVeaCOHfbKGmIpaQYX4XLxPaK0uyhLK:XGFVQckAUGTBtOHfufIpaQ+4lPJnyhLK - TLSH:
T13532AEF750A7DC887D965B17ADAA10696087D38C223296A048CCB73DC0BC6FDBE11971 - Submitted as: 56163000455.pdf
- File type: pdf · Size: 45948 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://cctraff.ru/strik?keyword=greenhouse+gases+and+their+sources+pdf, https://uploads.strikinglycdn.com/files/766fbcba-008d-43c7-9e12-69bdc5b71af0/jabamene.pdf, https://uploads.strikinglycdn.com/files/054d6f76-3505-4434-8b1d-c8e3b452ac3e/dizininumo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=greenhouse+gases+and+their+sources+pdf
- https://uploads.strikinglycdn.com/files/766fbcba-008d-43c7-9e12-69bdc5b71af0/jabamene.pdf
- https://uploads.strikinglycdn.com/files/054d6f76-3505-4434-8b1d-c8e3b452ac3e/dizininumo.pdf
- https://uploads.strikinglycdn.com/files/355e1afb-9514-4909-94e3-c00582f8974e/fipotonowuluguvunulotiwul.pdf
- https://uploads.strikinglycdn.com/files/bacb230d-b688-4c81-89d4-263fa9716d2e/10587118433.pdf
- https://uploads.strikinglycdn.com/files/de05f2d7-4452-4409-a162-dd3b3ad75c76/56822983494.pdf
- https://uploads.strikinglycdn.com/files/7ebd0a64-1afe-401b-85d8-8370c410994f/fowoxuwojiki.pdf
- https://uploads.strikinglycdn.com/files/9a74f7d5-12ad-4c41-9d54-c7e130e1bea1/18040036671.pdf
- https://uploads.strikinglycdn.com/files/cc0c49aa-7760-4692-a846-db50e1062e13/9529493865.pdf
- http://pivog.providencerescuemission.org/uploads/1/3/1/8/131871991/pixubipikoparigu.pdf
- http://bojun.rutheverett.com/uploads/1/3/2/6/132681692/ca776e53.pdf
- http://files.noscopegaming.net/uploads/1/3/1/3/131398295/8798582.pdf
- http://files.oshkoshmainstreetmusicfestival.com/uploads/1/3/2/7/132740580/peximuxi_fexir.pdf
- http://files.neighbourlinkck.com/uploads/1/3/0/8/130813898/gufefobupij_sapujobiw_jagobulafonem.pdf
- http://files.mrspoolsbearcatclasses.com/uploads/1/3/1/3/131379894/9b375c55efe.pdf
- http://files.ridingisgood.com/uploads/1/3/0/8/130873826/ketaf.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- pivog.providencerescuemission.org
- bojun.rutheverett.com
- files.noscopegaming.net
- files.oshkoshmainstreetmusicfestival.com
- files.neighbourlinkck.com
- files.mrspoolsbearcatclasses.com
- files.ridingisgood.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report