SUSPICIOUS — 40898610613.pdf
SUSPICIOUS — 40898610613.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
5a43bcc99933fcef3e0f3bfddc4245d8252a1f141c1a1fe183ef4e1cbbf80508 - SHA-1:
03253a88bf1d277e0f757361e91fc79d0273e834 - MD5:
0c11157021dfba5545cc7263c8c990f0 - ssdeep:
768:ydgGzpDip3AIPfevljXaj+prS5rCPIixCLVnS7RHtmeb/N8yzM51ZUgMHk5:FGF2pTyprS5lixCLlS7nm6l8yI51ZPMy - TLSH:
T168318DF3409BED4C798AAB039DF71559614AD3886233A360198C3B6DC5BC6BDAF10960 - Submitted as: 40898610613.pdf
- File type: pdf · Size: 42318 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=oxford+spoken+english+books+pdf+free+download, https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/85f5a0.pdf, https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/9247351.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=oxford+spoken+english+books+pdf+free+download
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/85f5a0.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/9247351.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/caa64.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/zuvefusu_tewojawowebav.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/bawap.pdf
- https://uploads.strikinglycdn.com/files/f3394647-c17a-40f3-9012-3933d8a0dd06/soxigomeg.pdf
- https://uploads.strikinglycdn.com/files/3d1434eb-3f5c-4ac2-ade1-8a726ea44148/89707782358.pdf
- https://uploads.strikinglycdn.com/files/0e351dce-e5f3-4804-af4d-c994b24f4537/22647870677.pdf
- https://uploads.strikinglycdn.com/files/d09896ef-d23a-4181-892d-366c883d3f94/kikuneli.pdf
- https://uploads.strikinglycdn.com/files/e2cca0a5-4c1f-4e47-89fa-134f69efb2e6/difikabisazudubaliwisaw.pdf
- https://cdn.shopify.com/s/files/1/0437/4082/3706/files/sajiwixotigovutibut.pdf
- https://cdn.shopify.com/s/files/1/0437/8696/1045/files/jolerirugasorikirit.pdf
- https://cdn.shopify.com/s/files/1/0496/2484/2391/files/lizowagilifugixix.pdf
- https://cdn.shopify.com/s/files/1/0433/4610/0392/files/tefafigoda.pdf
- https://uploads.strikinglycdn.com/files/b22e5809-522b-4948-af8a-5369c3609eda/judumoraso.pdf
- https://uploads.strikinglycdn.com/files/0996377e-0a2c-4326-9e53-9b3e1c52fa32/welati.pdf
- https://uploads.strikinglycdn.com/files/1f66ca3c-9472-443d-8d22-32a757fcf0f2/liporabupezab.pdf
- https://uploads.strikinglycdn.com/files/7fd4fd08-c556-4d51-9320-6ea0234e0a56/653127841.pdf
- https://uploads.strikinglycdn.com/files/e1567728-17c6-4215-95d2-9e07266ef8be/25397490452.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- mojivimimujovo.weebly.com
- fijojonibiw.weebly.com
- dimaxafazeza.weebly.com
- jawasolasazilem.weebly.com
- jatorogerujew.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report