SUSPICIOUS — 83297583646.pdf
SUSPICIOUS — 83297583646.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
48c6727aa237171e9434069848de5602ad40e2f570624036d148aa52d25f828a - SHA-1:
c11cb95b9831bdd6d82aecbcbe42fc0b6884612b - MD5:
e2d3a26a1004f69089542eff5fe735f8 - ssdeep:
768:fgGzpD0+t5c3uZUphqPtBYldmjt/LOQBJdpVyhmWyei7AEU3vLe+6bN:oGFQOKBj8iSJduhmoi7AEgvq+6bN - TLSH:
T18C34AEF35067ED8C768BAF47DEE61148610AD3886236DBA044C9772CC47C6BC7E44A61 - Submitted as: 83297583646.pdf
- File type: pdf · Size: 53987 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=ccna+security+chapter+5+exam+answers+2019, https://uploads.strikinglycdn.com/files/a497a7c9-bab4-4c54-a8c8-7c0871a67ede/wapewisegokuwir.pdf, https://uploads.strikinglycdn.com/files/bdc7f7d6-7b05-4f7a-97fc-ae0ec4dcaf49/joruna.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=ccna+security+chapter+5+exam+answers+2019
- https://uploads.strikinglycdn.com/files/a497a7c9-bab4-4c54-a8c8-7c0871a67ede/wapewisegokuwir.pdf
- https://uploads.strikinglycdn.com/files/bdc7f7d6-7b05-4f7a-97fc-ae0ec4dcaf49/joruna.pdf
- https://uploads.strikinglycdn.com/files/88d25a4e-ba8a-464a-a898-3d50d37d7e23/47426217491.pdf
- https://uploads.strikinglycdn.com/files/4292e54e-81e7-4c9f-b3bc-14386dd02c2f/fuvuxilezulis.pdf
- https://uploads.strikinglycdn.com/files/3918b274-29fc-4978-99ec-f4c513f42370/wotatajagotolotepowefumu.pdf
- http://sigof.frommairpad.com/uploads/1/3/0/8/130814085/tazadupulakenub-wazuvaliw.pdf
- http://files.jamesdykman.com/uploads/1/3/1/4/131452817/4326600.pdf
- http://files.camppepper.com/uploads/1/3/2/3/132302913/1217584.pdf
- https://site-1039800.mozfiles.com/files/1039800/79563398100.pdf
- https://site-1037101.mozfiles.com/files/1037101/90243840082.pdf
- https://site-1041082.mozfiles.com/files/1041082/muvidafugepix.pdf
- https://site-1036955.mozfiles.com/files/1036955/zovutumivowapigifoma.pdf
- https://uploads.strikinglycdn.com/files/88c6df5b-b82c-474d-a2ea-0d8551c68c80/peseritijusezemomugibine.pdf
- https://uploads.strikinglycdn.com/files/c12a02ae-70ca-4364-8f48-6b7dadc13d3f/55513245755.pdf
- https://uploads.strikinglycdn.com/files/efd288b3-cfa0-4731-98cf-40103ad61019/tevugabebiviwejilovoz.pdf
- https://uploads.strikinglycdn.com/files/bf2f3169-52a9-4d3a-bbd1-eff5dea829d6/fovekekuxuton.pdf
- https://uploads.strikinglycdn.com/files/5a38aac7-0e57-49fd-a8ad-5d4f866fe620/24311808007.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- sigof.frommairpad.com
- files.jamesdykman.com
- files.camppepper.com
- site-1039800.mozfiles.com
- site-1037101.mozfiles.com
- site-1041082.mozfiles.com
- site-1036955.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report