SUSPICIOUS — 79367730946.pdf
SUSPICIOUS — 79367730946.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
7fcd2766dd2b96f0adbad481012cc9a1eca5aaa92328914f4d9aa1f1636acd5e - SHA-1:
ba7e4522993f7c523cd398324f147f03bde490ad - MD5:
ddfc5576c60754634c1eb5b60819f26c - ssdeep:
768:pgGzpD6jgpz2CGjC2GDwD3/rOmMffgXlPWlTIs:KGF4qVGj+w7zOmMH2lP2TIs - TLSH:
T1B7308CF3606BED8C698AAB47ADF601655546C78C6223AB7418CC7B3CC47C2BDAE00911 - Submitted as: 79367730946.pdf
- File type: pdf · Size: 36999 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=pharmacokinetics+made+easy+birkett+pdf, http://kavod.barbarabickmore.com/uploads/1/3/2/6/132682871/nisoverekijudutiraf.pdf, http://jobax.operabarcarola.com/uploads/1/3/0/7/130775643/d7586edf8d62bc0.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=pharmacokinetics+made+easy+birkett+pdf
- http://kavod.barbarabickmore.com/uploads/1/3/2/6/132682871/nisoverekijudutiraf.pdf
- http://jobax.operabarcarola.com/uploads/1/3/0/7/130775643/d7586edf8d62bc0.pdf
- http://vabixewu.candicekaras.com/uploads/1/3/1/0/131070491/bedub-ramovezaji-vigiboj.pdf
- https://cdn.shopify.com/s/files/1/0487/9227/3061/files/eliminator_weed_killer_concentrate.pdf
- https://site-1039785.mozfiles.com/files/1039785/62670696712.pdf
- https://site-1037274.mozfiles.com/files/1037274/1931135093.pdf
- https://site-1037215.mozfiles.com/files/1037215/22685267790.pdf
- https://uploads.strikinglycdn.com/files/f004c6e2-24d4-447f-bf3c-fb3f41cfb7ff/lazekowonozut.pdf
- https://uploads.strikinglycdn.com/files/e997bfb6-b120-43ff-9313-154697e6cea4/11576365554.pdf
- https://uploads.strikinglycdn.com/files/3446e3c7-3314-4187-8e4c-1d5a16588a2d/90747962173.pdf
- https://uploads.strikinglycdn.com/files/0143e56c-d8f4-4d68-ab7b-c65e463cee0b/wumoxasibe.pdf
- https://uploads.strikinglycdn.com/files/ee0c1092-f9cf-46c4-b599-6e84c2d43e38/32564677576.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- kavod.barbarabickmore.com
- jobax.operabarcarola.com
- vabixewu.candicekaras.com
- cdn.shopify.com
- site-1039785.mozfiles.com
- site-1037274.mozfiles.com
- site-1037215.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report