SUSPICIOUS — 93000563081.pdf
SUSPICIOUS — 93000563081.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
766452208fbba8d95812b6c422afe0e726d0db5dcd20be22a9232cb3a51b3863 - SHA-1:
3e7071db187dcf562c2d013c3f0a42bbab0a47b2 - MD5:
9bc409b4181a7cac7f7c89b3d73a9e0b - ssdeep:
768:NgGzpDoVtDnVn2xfRpc6ZptmGiARldsht4M5GJu5qW5zRgut96:uGF0VKE6ZpwQXsf4M5WMqW5zaut96 - TLSH:
T1CB328DF30167CD8C7AC7AB435DEA2558A146E74D6122A7A484D9BB7DC07C2BC7F01A20 - Submitted as: 93000563081.pdf
- File type: pdf · Size: 44330 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=que+es+un+sistema+monousuario, https://uploads.strikinglycdn.com/files/1c93a53a-48e1-4205-b378-f1ee10cb2ff4/26110392038.pdf, https://uploads.strikinglycdn.com/files/b9e0106c-73fb-4862-8929-059bd206c553/63537562592.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=que+es+un+sistema+monousuario
- https://uploads.strikinglycdn.com/files/1c93a53a-48e1-4205-b378-f1ee10cb2ff4/26110392038.pdf
- https://uploads.strikinglycdn.com/files/b9e0106c-73fb-4862-8929-059bd206c553/63537562592.pdf
- https://uploads.strikinglycdn.com/files/c1bd281e-d41d-4542-8f99-23783a03d251/10289894235.pdf
- https://uploads.strikinglycdn.com/files/48b72732-d125-401b-9298-d0a83c3c2b06/22150862837.pdf
- https://uploads.strikinglycdn.com/files/9efe0a4e-d581-4b6b-8cad-7aa31e41cb52/45221119338.pdf
- https://site-1037113.mozfiles.com/files/1037113/nolikalarigurelipofulul.pdf
- http://files.jonchandler.com/uploads/1/3/0/7/130739978/fexapi.pdf
- http://files.rsitoy.com/uploads/1/3/0/7/130738801/muvagiribi.pdf
- https://site-1037048.mozfiles.com/files/1037048/pexavasosidosavalukizole.pdf
- https://site-1037069.mozfiles.com/files/1037069/simodafaxa.pdf
- https://site-1037172.mozfiles.com/files/1037172/80944063758.pdf
- https://site-1039498.mozfiles.com/files/1039498/someloperalekure.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1037113.mozfiles.com
- files.jonchandler.com
- files.rsitoy.com
- site-1037048.mozfiles.com
- site-1037069.mozfiles.com
- site-1037172.mozfiles.com
- site-1039498.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report