SUSPICIOUS — 2470711406.pdf
SUSPICIOUS — 2470711406.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
1bc24c9704ae1b45b31e2081d9b8809111e1b2b9dd4a9482f262b3f93e8c8ba5 - SHA-1:
6e9431b4f7398c7f0c11b516ce72439c700636f1 - MD5:
411234725d8e3c12770b652724bbb9aa - ssdeep:
1536:RGFepb1Vormo5C44yebX0m5HLefN36+2oMsrl8kWBI594Zx:0Fepx2r/5C44vLLK36+2oMc89I59w - TLSH:
T10C349EF35097ED4C7BCBAB03ACAB00A9554AC68D7133EA905488772CD17CAFE6E11950 - Submitted as: 2470711406.pdf
- File type: pdf · Size: 56484 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=misterios+del+rosario+dia+jueves, https://uploads.strikinglycdn.com/files/dcf6b0da-4ad6-4f24-9d57-e63153680c25/7017209730.pdf, https://uploads.strikinglycdn.com/files/b73d4822-f090-4a20-a0fb-d862142d3fab/89289030505.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=misterios+del+rosario+dia+jueves
- https://uploads.strikinglycdn.com/files/dcf6b0da-4ad6-4f24-9d57-e63153680c25/7017209730.pdf
- https://uploads.strikinglycdn.com/files/b73d4822-f090-4a20-a0fb-d862142d3fab/89289030505.pdf
- https://uploads.strikinglycdn.com/files/a10b7f90-a65e-4a6e-8fc2-a062ffa82d42/midesedexevosebadupoja.pdf
- https://cdn.shopify.com/s/files/1/0477/3734/0060/files/sanuzurabodobexe.pdf
- https://cdn.shopify.com/s/files/1/0486/3875/4974/files/rekikisugisogabokivulu.pdf
- https://cdn.shopify.com/s/files/1/0497/7888/4759/files/ultra4_offroad_racing_apk_mod.pdf
- https://uploads.strikinglycdn.com/files/4dac0aaf-5723-4336-9449-1a80601814d1/38521755709.pdf
- https://uploads.strikinglycdn.com/files/9a488236-cac6-46a1-830c-7acb3146b9d6/wasepufiderikiti.pdf
- https://uploads.strikinglycdn.com/files/972d8131-a0ad-42bf-8a5d-c2bd70de0964/adobe_illustrator_free_italiano_mac.pdf
- https://uploads.strikinglycdn.com/files/aec07b6c-b551-4cf8-8eac-8e427d8213a9/sanugeguzomavifeme.pdf
- https://uploads.strikinglycdn.com/files/64d21986-5d56-4301-a228-8a0b02236b12/jazakuvewarololafola.pdf
- https://cdn-cms.f-static.net/uploads/4383577/normal_5f91fa87e5b9c.pdf
- https://cdn-cms.f-static.net/uploads/4366339/normal_5f87328f8c1f7.pdf
- https://cdn-cms.f-static.net/uploads/4376088/normal_5f8a2308e1e0b.pdf
- https://cdn.shopify.com/s/files/1/0498/3432/8219/files/tilesaxijexu.pdf
- https://cdn.shopify.com/s/files/1/0491/8791/3894/files/angles_in_polygons_questions_and_answers.pdf
- https://cdn.shopify.com/s/files/1/0462/7166/0189/files/electrical_distribution_system_protection.pdf
- https://cdn-cms.f-static.net/uploads/4366017/normal_5f873cc856f56.pdf
- https://cdn-cms.f-static.net/uploads/4383561/normal_5f8d9ff55bce9.pdf
- https://cdn-cms.f-static.net/uploads/4375503/normal_5f902e1fc8307.pdf
- https://cdn-cms.f-static.net/uploads/4386609/normal_5f8cc7e82caf4.pdf
- https://cdn-cms.f-static.net/uploads/4377933/normal_5f8f9b814480d.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report