SUSPICIOUS — 95039458473.pdf
SUSPICIOUS — 95039458473.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
4d43b03af46c5caec90bbded309fa5f47effd7acbec8cf308339b8d5c2d0b8ff - SHA-1:
5156931369e76d10bfb03431f5b25d924bba5c9f - MD5:
c1caa6a63e19ae050e12787219741535 - ssdeep:
768:gUgGzpDuphGnptXkMLOWjYtw7xQaXCbaq/8wNoKLDTrigaZ8zIjGSm2UUBJe4EYo:YGF6pmAb3NoKrrigC8F2FJe4L8Qe1PCC - TLSH:
T1CA31AEF75497ED8C3B438B13ADAA1019118ECB8D6036ABA05498772DC5BC3ED6F40A70 - Submitted as: 95039458473.pdf
- File type: pdf · Size: 42851 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=norton+commander+download+android, https://cdn-cms.f-static.net/uploads/4366340/normal_5f87666455b7c.pdf, https://cdn-cms.f-static.net/uploads/4366367/normal_5f8738d98f38b.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=norton+commander+download+android
- https://cdn-cms.f-static.net/uploads/4366340/normal_5f87666455b7c.pdf
- https://cdn-cms.f-static.net/uploads/4366367/normal_5f8738d98f38b.pdf
- https://cdn-cms.f-static.net/uploads/4366668/normal_5f877e52deddc.pdf
- https://cdn-cms.f-static.net/uploads/4367007/normal_5f873222e6869.pdf
- https://cdn-cms.f-static.net/uploads/4366384/normal_5f8752687829b.pdf
- https://cdn-cms.f-static.net/uploads/4365591/normal_5f876cc7ba021.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/dekefomivupe-kovak-talajonipa-fedebiraroz.pdf
- https://punadojum.weebly.com/uploads/1/3/2/6/132680976/gowonavigevezik.pdf
- https://cdn.shopify.com/s/files/1/0430/3683/5993/files/66564414785.pdf
- https://cdn.shopify.com/s/files/1/0501/9464/5173/files/self_awareness_books.pdf
- https://cdn.shopify.com/s/files/1/0266/8281/8751/files/91233970579.pdf
- https://cdn.shopify.com/s/files/1/0482/8738/3714/files/the_living_christmas_company_shark_tank_update.pdf
- https://cdn.shopify.com/s/files/1/0268/8604/5889/files/rails_devise_send_reset_password_instructions.pdf
- https://cdn.shopify.com/s/files/1/0497/8881/3461/files/love_her_wild_atticus_free_download.pdf
- https://cdn-cms.f-static.net/uploads/4365598/normal_5f870c00d2d06.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f8773cce6e83.pdf
- https://cdn-cms.f-static.net/uploads/4366311/normal_5f872acd202e6.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- zoxuzuxebexot.weebly.com
- punadojum.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report