SUSPICIOUS — 35300256837.pdf
SUSPICIOUS — 35300256837.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
72b6d44f5c13b501052d01fa54758fa74db29da1c1b7f213d0278a386282430c - SHA-1:
720a816c189f5bc69c902115ec24d6554f1daa20 - MD5:
050f6aade6709d1b6bb6277e8c17b2f1 - ssdeep:
1536:NGFL7hiOTak/PRV6wWhONQqEcW2PbrFXhin00CnEB:QFL7L2kv6w4wQBKPbrFXon0PnC - TLSH:
T1F036AFF31557DEAC6F82ABC318B6F2592025AA842161F67484C4FA6C847C3BE6F14D70 - Submitted as: 35300256837.pdf
- File type: pdf · Size: 64512 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=tabla+de+trigonometria+seno, https://site-1037224.mozfiles.com/files/1037224/gowapabuzutonubikutewixaz.pdf, https://site-1038358.mozfiles.com/files/1038358/43741393125.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=tabla+de+trigonometria+seno
- https://site-1037224.mozfiles.com/files/1037224/gowapabuzutonubikutewixaz.pdf
- https://site-1038358.mozfiles.com/files/1038358/43741393125.pdf
- https://site-1044154.mozfiles.com/files/1044154/74940798996.pdf
- https://uploads.strikinglycdn.com/files/6a21bd47-f0e0-46a8-8440-7ea8e391b888/19712348879.pdf
- https://uploads.strikinglycdn.com/files/1d78dc5c-511c-4478-8c16-0c2c84657257/zadasozifegip.pdf
- https://uploads.strikinglycdn.com/files/88defb70-d537-4c36-9f14-081442b027dc/33023926092.pdf
- https://uploads.strikinglycdn.com/files/0b45bd03-b527-49af-b200-620432f56a4d/2012337212.pdf
- https://uploads.strikinglycdn.com/files/e42d7820-b369-4e1d-818d-29055ea14fc0/68754067798.pdf
- https://uploads.strikinglycdn.com/files/bc6e7451-b18a-428d-a4c2-1ceb56536987/divurabiwofe.pdf
- https://uploads.strikinglycdn.com/files/204031dc-9c8e-4eaf-816b-c616112d2d94/7796907158.pdf
- https://uploads.strikinglycdn.com/files/b2683818-51da-4346-9252-8bca89dfd6cd/27219900417.pdf
- https://uploads.strikinglycdn.com/files/dd34eece-448b-41ab-bfed-d0a850a34af3/xazezolojej.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1037224.mozfiles.com
- site-1038358.mozfiles.com
- site-1044154.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report