SUSPICIOUS — 91360174666.pdf
SUSPICIOUS — 91360174666.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
7921e2920c580507f66cec071573f234d51bbf44526be355af55011e373a5eb9 - SHA-1:
a6f6f4dd7ecefeb162adffe75524f4c41bee04f7 - MD5:
c15f996afcab60704f865abc3a35cb21 - ssdeep:
768:vgGzpDeivzH/Pwr7y8kIWqKmm7+QBx3k7xSkwa0p7ggVT8:YGFyi4y8kILKvJ73k7EdP7FVT8 - TLSH:
T175339DF7419BDC8C7A87BB1369F60159524AC68C2233AB60589CBB2DC97C5BC7F10921 - Submitted as: 91360174666.pdf
- File type: pdf · Size: 48347 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=vidmate+old+version+app++uptodown.+com, https://cdn.shopify.com/s/files/1/0435/4048/0164/files/reliable_ticket_sites.pdf, https://cdn.shopify.com/s/files/1/0437/5999/2993/files/bernards_high_school_athletics.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=vidmate+old+version+app++uptodown.+com
- https://cdn.shopify.com/s/files/1/0435/4048/0164/files/reliable_ticket_sites.pdf
- https://cdn.shopify.com/s/files/1/0437/5999/2993/files/bernards_high_school_athletics.pdf
- https://cdn.shopify.com/s/files/1/0484/8720/2971/files/the_teenagers_guide_to_the_real_world.pdf
- https://site-1036867.mozfiles.com/files/1036867/84241010684.pdf
- https://site-1036921.mozfiles.com/files/1036921/57872728666.pdf
- https://site-1038670.mozfiles.com/files/1038670/52497518857.pdf
- http://kilab.jericosoundsystems.com/uploads/1/3/1/4/131407014/fifapux.pdf
- http://medem.livingforlivestock.com/uploads/1/3/1/8/131857101/guzar_nukisunexapeban_jomapilafew.pdf
- http://pumewo.brendadater.com/uploads/1/3/2/7/132741024/1fec1ad1.pdf
- http://kopefi.upholsteringmelbourne.com.au/uploads/1/3/0/8/130873946/befigulevom_torewijomubebu_mobobosabukila.pdf
- https://uploads.strikinglycdn.com/files/01ea0bea-575a-4c01-a1a1-d71aa70300bf/29644514378.pdf
- https://uploads.strikinglycdn.com/files/5425e07b-bb02-4581-b9f6-90d583eed392/92421139321.pdf
- https://uploads.strikinglycdn.com/files/af89da73-60da-46ca-b5c1-b98422f72a15/63527285469.pdf
- https://uploads.strikinglycdn.com/files/7cdbd610-7c14-47d3-ac1b-066e074c02f7/kuxulexewuzuwa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- site-1036867.mozfiles.com
- site-1036921.mozfiles.com
- site-1038670.mozfiles.com
- kilab.jericosoundsystems.com
- medem.livingforlivestock.com
- pumewo.brendadater.com
- kopefi.upholsteringmelbourne.com.au
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report