SUSPICIOUS — 37923091023.pdf
SUSPICIOUS — 37923091023.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
2358fa42aa08b5e8fb0bf10fd2c12533be4b1bfe4172f6871400f00e4e01749c - SHA-1:
64450e1b7f648ada6b7211527460ded85cfb791b - MD5:
434a3978661990ffe4f6ef30be097ad6 - ssdeep:
768:7gGzpDVCdCwnTXMAyWI8Nb/ze88Hhm8AxJngxQqCnndiGoHz4jkjTPHqojTPH5jS:EGFxCNCpHHAzgxWndiGoTqGTvq6TvdT2 - TLSH:
T17B319EF71497EC8C7A8B9B13AEE6246A6149C28C6233D760458C7B2CD53C5FE3E50960 - Submitted as: 37923091023.pdf
- File type: pdf · Size: 42470 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=the+role+of+budgeting+in+management+planning+and+control+pdf, https://cdn.shopify.com/s/files/1/0482/8286/1729/files/48436189015.pdf, https://cdn.shopify.com/s/files/1/0431/1102/2756/files/bejomelopozijakoxipasemo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=the+role+of+budgeting+in+management+planning+and+control+pdf
- https://cdn.shopify.com/s/files/1/0482/8286/1729/files/48436189015.pdf
- https://cdn.shopify.com/s/files/1/0431/1102/2756/files/bejomelopozijakoxipasemo.pdf
- https://cdn.shopify.com/s/files/1/0429/1428/3686/files/58343157073.pdf
- https://cdn.shopify.com/s/files/1/0433/8683/0998/files/32144210138.pdf
- https://cdn.shopify.com/s/files/1/0427/7954/1671/files/juputabavidarekuret.pdf
- https://cdn.shopify.com/s/files/1/0447/9565/8389/files/credit_risk_modelling_springer.pdf
- https://cdn.shopify.com/s/files/1/0433/3636/8296/files/direct_variation_formula_variables.pdf
- https://cdn.shopify.com/s/files/1/0463/2913/5265/files/impact_factor_surface_science_reports.pdf
- https://cdn.shopify.com/s/files/1/0427/8494/8380/files/capitalize_prepositions_in_titles_chicago_manual.pdf
- https://cdn.shopify.com/s/files/1/0435/2403/0618/files/pdf_file_format_error.pdf
- https://uploads.strikinglycdn.com/files/78a39143-4529-46d9-a8c3-ee3e1bee2d04/94940219847.pdf
- https://uploads.strikinglycdn.com/files/d2b1bf79-82e8-4947-ad15-60d3efce2fb6/50045700586.pdf
- https://uploads.strikinglycdn.com/files/205d33b3-e31b-4155-91ea-d823c2764467/70740343407.pdf
- https://uploads.strikinglycdn.com/files/0828349b-8a1c-4c9c-aac4-9557577b4d1e/31273163489.pdf
- http://files.combotlab.org/uploads/1/3/1/4/131454452/tapusowuxewal-diwakuvim-kadotivufenuvo-wuxusijapotofit.pdf
- http://files.karlyperez.com/uploads/1/3/0/8/130814714/puvesu-dilakinenisam-maxajake.pdf
- http://lixoxuxif.multidimensionalchromatography.com/uploads/1/3/1/3/131383914/rosij_zorelademe_sezemomi_xovived.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- files.combotlab.org
- files.karlyperez.com
- lixoxuxif.multidimensionalchromatography.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report