SUSPICIOUS — liner.pdf
SUSPICIOUS — liner.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
56c631e888619e8bf8564b9d60dfd710066765a7362b703e6bc884cdf618151a - SHA-1:
82210b8ee424bb34c5d4d107c1a41b8dc8fcb7b8 - MD5:
21fec7977e194016b178678c4908d87d - ssdeep:
768:/gGzpDmjtOekB0fNbOqAF8xq+L9xatFMxGB5Y5yyzztyJ4dJZvo/QMlMw:IGFaUB0Vb1AubLP0MxGB5Ypzzul/QMiw - TLSH:
T1B2339EF31197DC4C794E6F479EE6106D619AD78C213292A09AC8362DC0BCAFD7F10A21 - Submitted as: liner.pdf
- File type: pdf · Size: 47587 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=big+o+notation+examples+in+data+structure+pdf, https://site-1037164.mozfiles.com/files/1037164/febalarabakazomumivus.pdf, https://site-1036807.mozfiles.com/files/1036807/kuwikutedujodor.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=big+o+notation+examples+in+data+structure+pdf
- https://site-1037164.mozfiles.com/files/1037164/febalarabakazomumivus.pdf
- https://site-1036807.mozfiles.com/files/1036807/kuwikutedujodor.pdf
- https://site-1036731.mozfiles.com/files/1036731/31043722305.pdf
- https://site-1037283.mozfiles.com/files/1037283/27249080381.pdf
- https://site-1037075.mozfiles.com/files/1037075/mumebezesilagevivuvefe.pdf
- https://uploads.strikinglycdn.com/files/c305a319-8ee6-4a67-a0c9-3258ce054da0/50412853297.pdf
- https://uploads.strikinglycdn.com/files/f6893621-c958-4916-b161-d67cc1eea1e6/99927257849.pdf
- https://uploads.strikinglycdn.com/files/5e8ebc73-5b1f-40e4-b3a8-1c0190d389b0/punuvegud.pdf
- https://uploads.strikinglycdn.com/files/1f259589-a808-4c23-91a1-3e59944c0644/20583301178.pdf
- https://uploads.strikinglycdn.com/files/ab6c145e-91aa-4def-9434-ecb372f01999/32443419715.pdf
- https://uploads.strikinglycdn.com/files/00674bc3-eb5b-4b65-8db0-78bc1bd97f6a/49365849401.pdf
- https://uploads.strikinglycdn.com/files/06578b9a-0c11-48a8-87c9-5dd65e22ecef/2144076389.pdf
- https://uploads.strikinglycdn.com/files/45198ecf-cf82-4360-a097-fbc3704b91bc/85372029204.pdf
- https://site-1037215.mozfiles.com/files/1037215/81718468282.pdf
- https://site-1037184.mozfiles.com/files/1037184/89263703095.pdf
- https://site-1037106.mozfiles.com/files/1037106/polulot.pdf
- https://site-1037094.mozfiles.com/files/1037094/pasesanodomom.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1037164.mozfiles.com
- site-1036807.mozfiles.com
- site-1036731.mozfiles.com
- site-1037283.mozfiles.com
- site-1037075.mozfiles.com
- uploads.strikinglycdn.com
- site-1037215.mozfiles.com
- site-1037184.mozfiles.com
- site-1037106.mozfiles.com
- site-1037094.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report