SUSPICIOUS — 38350585334.pdf
SUSPICIOUS — 38350585334.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
4a9f1ff8060dc8c261aa3153d3aa2cfd6ebbbe22594ff5dd04bb2a62373d6705 - SHA-1:
607c5c3611f0663f3f7dce166074c51ccb117d7b - MD5:
d170314a9ebce192c2ec0f6d04fe4231 - ssdeep:
768:IgGzpDOvL3ddaCiPwfE/E1FLiTjX32hwUdqr9cPJsSp3eru8Q2hdF4:FGF6vrLKczcz3Agr9cx3yQ2hD4 - TLSH:
T16433AFF310A7EF0C7A8B5F43AEA601856409D689713287A0598C7BACC1BC2FE6F54D51 - Submitted as: 38350585334.pdf
- File type: pdf · Size: 51989 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=exerc%25C3%25ADcios+de+tipologia+textual, https://site-1037212.mozfiles.com/files/1037212/nojirasezubutanub.pdf, https://site-1039661.mozfiles.com/files/1039661/96733314216.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=exerc%25C3%25ADcios+de+tipologia+textual
- https://site-1037212.mozfiles.com/files/1037212/nojirasezubutanub.pdf
- https://site-1039661.mozfiles.com/files/1039661/96733314216.pdf
- https://site-1037260.mozfiles.com/files/1037260/kojeji.pdf
- https://uploads.strikinglycdn.com/files/f9505578-5385-4413-a3cd-e502b24b2687/70692364345.pdf
- https://uploads.strikinglycdn.com/files/28b4c28c-0977-424a-b194-23110057bc36/98031756246.pdf
- https://uploads.strikinglycdn.com/files/2452cc03-0ea4-4dbf-9f85-f3f813664870/72886351550.pdf
- https://uploads.strikinglycdn.com/files/6ba386a3-2f8b-473f-81dd-c5166218a616/45698517943.pdf
- http://vobokiza.daniellebaldassari.com/uploads/1/3/0/8/130874284/8287390.pdf
- http://files.readywritercsb.com/uploads/1/3/1/1/131164238/relemujirod-wolet.pdf
- http://files.respectthesnake.com/uploads/1/3/0/9/130969283/safatabuzezi.pdf
- http://files.bardgames.org/uploads/1/3/1/8/131872273/96cb91041e57.pdf
- http://files.margueriteperret.com/uploads/1/3/0/7/130776177/rumemoxege.pdf
- http://xegupo.fingerhutcakes.com/uploads/1/3/1/4/131438397/aa9d4f.pdf
- http://files.lumenctr.org/uploads/1/3/1/8/131871796/vatebobunaxu-sikuzoxupe-xebenujin-neruzomusame.pdf
- http://files.sthelenasportsday.com/uploads/1/3/1/0/131070590/rusonaxalivale.pdf
- http://nijesase.rescuetheunderdog.com/uploads/1/3/0/7/130775598/8217319.pdf
- http://files.rmxelite.com/uploads/1/3/1/6/131606487/3466267.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1037212.mozfiles.com
- site-1039661.mozfiles.com
- site-1037260.mozfiles.com
- uploads.strikinglycdn.com
- vobokiza.daniellebaldassari.com
- files.readywritercsb.com
- files.respectthesnake.com
- files.bardgames.org
- files.margueriteperret.com
- xegupo.fingerhutcakes.com
- files.lumenctr.org
- files.sthelenasportsday.com
- nijesase.rescuetheunderdog.com
- files.rmxelite.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report