SUSPICIOUS — 87036197691.pdf
SUSPICIOUS — 87036197691.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
3d1118557300f00c1fbacd3d45db0a5402eee439f07e507358f68fabe4e771fd - SHA-1:
49d2ecfc1e6967210868efd44746793411caed3c - MD5:
9a934910789b393091b638a6c669fa79 - ssdeep:
1536:EGF85XBwAs1SKRyL1W3kKMXBuSXI2WLr11B:RF8cBSPPKqQSax - TLSH:
T104339EF340D7EC4C7787AB136EAA112DA18ADB4C2132D7A0589C7B2CC87C5BC6E51991 - Submitted as: 87036197691.pdf
- File type: pdf · Size: 50866 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=average+wage+in+ireland, https://cdn-cms.f-static.net/uploads/4386095/normal_5f8cb7772107c.pdf, https://uploads.strikinglycdn.com/files/34e049fa-de5b-4dea-973f-4b384b6b35b7/paraiso_aventura_las_huertas_tlaquiltenango_mor.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=average+wage+in+ireland
- https://cdn-cms.f-static.net/uploads/4386095/normal_5f8cb7772107c.pdf
- https://uploads.strikinglycdn.com/files/34e049fa-de5b-4dea-973f-4b384b6b35b7/paraiso_aventura_las_huertas_tlaquiltenango_mor.pdf
- https://cdn.shopify.com/s/files/1/0432/0319/9138/files/direct_speech_reported_speech_exercises.pdf
- https://s3.amazonaws.com/libeganot/13934052961.pdf
- https://uploads.strikinglycdn.com/files/774732e5-feaf-4dd1-a17a-78a63b0336fb/lezotomiwuxadufekirupebe.pdf
- https://s3.amazonaws.com/xojafemori/79152197528.pdf
- https://cdn-cms.f-static.net/uploads/4370064/normal_5f88212134c3a.pdf
- https://s3.amazonaws.com/farezelof/gipovamavaxedonorojo.pdf
- https://cdn-cms.f-static.net/uploads/4365628/normal_5f8a004d90c9b.pdf
- https://cdn.shopify.com/s/files/1/0499/2417/8072/files/piwazoji.pdf
- https://cdn.shopify.com/s/files/1/0501/4913/0419/files/tx6_android_7_firmware.pdf
- https://uploads.strikinglycdn.com/files/f2a3bd8a-752f-42b5-b949-ed03e4a3e10b/managing_projects_a_team_based_approach.pdf
- https://cdn-cms.f-static.net/uploads/4393755/normal_5f92338b984fb.pdf
- https://cdn-cms.f-static.net/uploads/4366316/normal_5f94b11b6acb9.pdf
- https://cdn.shopify.com/s/files/1/0430/1396/3935/files/symbolism_in_lord_of_the_flies_chapter_4.pdf
- https://uploads.strikinglycdn.com/files/c5135bca-7c36-4bcf-ba27-b64fa752fff7/beauty_and_the_beast_tab.pdf
- https://uploads.strikinglycdn.com/files/ed5a5fdb-19f4-4027-9065-dd6f4c3f7bc8/pigumuwupalupi.pdf
- https://uploads.strikinglycdn.com/files/07ba675e-39f4-4eec-8ea4-22b6aeca9300/raporudiwitabezujiv.pdf
- https://s3.amazonaws.com/zuxadol/87908603570.pdf
- https://cdn.shopify.com/s/files/1/0430/4361/8965/files/allocation_unit_size_fat32_32gb_usb.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report