SUSPICIOUS — 25440224941.pdf
SUSPICIOUS — 25440224941.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
426aef9af936e9ca0e7cb318e449ed525c5325ae623b73064b17142efaaeef6b - SHA-1:
af2ac210f63ccc2e7044c0e16f5efd067e1eb5fb - MD5:
5e63f084e92976c0cce7a2fc4507fa6e - ssdeep:
768:KgGzpDmPK69D1U2TWIYHUtesWlvKTEEd9AxOw5zI2LXBXzm:XGFiZTWV0teXxsEWaOGzIwRXzm - TLSH:
T17F33CFF7A49AEE4CB2CB7B13ADB20025A209C64C6133833469D8726DC57C9FD7D60961 - Submitted as: 25440224941.pdf
- File type: pdf · Size: 51534 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=xenogenesis+harlan+ellison+pdf, https://uploads.strikinglycdn.com/files/02a3032a-497e-4940-a89b-20b6ed6f1142/paduv.pdf, https://uploads.strikinglycdn.com/files/8171baab-7146-48f3-b985-36e622480da4/kasoravoserovivamu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=xenogenesis+harlan+ellison+pdf
- https://uploads.strikinglycdn.com/files/02a3032a-497e-4940-a89b-20b6ed6f1142/paduv.pdf
- https://uploads.strikinglycdn.com/files/8171baab-7146-48f3-b985-36e622480da4/kasoravoserovivamu.pdf
- https://uploads.strikinglycdn.com/files/ae2c16cf-deb6-4b01-9506-25bae1811648/zureragobata.pdf
- https://uploads.strikinglycdn.com/files/ef2c94e3-d09f-494a-ba8e-da61244a3814/33122793191.pdf
- https://uploads.strikinglycdn.com/files/0ee720b3-7972-4bfb-a853-0bffb9b7a005/62601341359.pdf
- https://uploads.strikinglycdn.com/files/26350555-a40b-47c7-a929-33125c18b500/nirabarupirisabe.pdf
- https://site-1037867.mozfiles.com/files/1037867/24948673861.pdf
- https://site-1036855.mozfiles.com/files/1036855/noxiretakemotasinat.pdf
- https://site-1039727.mozfiles.com/files/1039727/65921310435.pdf
- https://cdn.shopify.com/s/files/1/0438/5678/9664/files/84013604189.pdf
- https://cdn.shopify.com/s/files/1/0433/3414/0056/files/5e_college_of_satire.pdf
- https://cdn.shopify.com/s/files/1/0431/2861/9168/files/latest_punjabi_movies_sites_list.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1037867.mozfiles.com
- site-1036855.mozfiles.com
- site-1039727.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report