SUSPICIOUS — 83042265345.pdf
SUSPICIOUS — 83042265345.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
1d0c076d9bf196956b081e51122602102d8391950531be130ae54e1a5c96423c - SHA-1:
8c701982440d894e634fc8ffe21340adbe05a647 - MD5:
b1c54e076cc752fc06982185f1e556ea - ssdeep:
768:bgGzpDVP5UtWKFztOX0skS45iTFTyi6CpKBsr/UOC6pT2SqnRyncnAmo:kGFBqJm0so5ihyCPrciMSqnRyncnAmo - TLSH:
T12B32AFF3109BEDCCAEC9AB436DE614962049C74C623397A418DD776D84B82BC6F05B60 - Submitted as: 83042265345.pdf
- File type: pdf · Size: 43931 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=past+simple+exercises+multiple+choice, https://uploads.strikinglycdn.com/files/be47595c-3bf3-4f6c-a34e-dc6d07ba6bfc/93009204768.pdf, https://uploads.strikinglycdn.com/files/a9de2503-ede2-453c-b89c-54a2fd9654ab/kojinunawuzigagapigi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=past+simple+exercises+multiple+choice
- https://uploads.strikinglycdn.com/files/be47595c-3bf3-4f6c-a34e-dc6d07ba6bfc/93009204768.pdf
- https://uploads.strikinglycdn.com/files/a9de2503-ede2-453c-b89c-54a2fd9654ab/kojinunawuzigagapigi.pdf
- https://uploads.strikinglycdn.com/files/d0801d43-cbeb-441f-8b79-27213d33ff7f/narepenututilevu.pdf
- https://uploads.strikinglycdn.com/files/f76f8eea-cdf3-49b2-8f0a-2fa3633d7118/rewisibudegulozitidoja.pdf
- https://uploads.strikinglycdn.com/files/acd30ea9-e802-4a6f-b01a-24a9d5e0d687/84107712099.pdf
- https://uploads.strikinglycdn.com/files/49419c96-fd7e-4918-953e-bbc3ae18f680/312369255.pdf
- https://uploads.strikinglycdn.com/files/ed434b36-a178-4884-bbdd-2ce504cd5439/32159033247.pdf
- http://files.brewablecafe.com/uploads/1/3/1/8/131871909/cced1.pdf
- http://files.psychedup.com.au/uploads/1/3/0/7/130738955/fidovewunamozet.pdf
- http://files.benmarshallwriter.com/uploads/1/3/0/7/130739474/1219030.pdf
- https://cdn.shopify.com/s/files/1/0436/9675/0742/files/dachshund_pumpkin_stencil.pdf
- https://cdn.shopify.com/s/files/1/0433/7709/8915/files/haier_wine_cooler_8_bottle.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- files.brewablecafe.com
- files.psychedup.com.au
- files.benmarshallwriter.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report