SUSPICIOUS — 01e60.pdf
SUSPICIOUS — 01e60.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
801ad3cc2b40809de7a436ea6197a3975cd1c661ba6297492c7d37a487080fcb - SHA-1:
5db2f8f700ad4f5880c76158011f842cacc2819b - MD5:
d2465e7950ea38ae10d8987e844310f1 - ssdeep:
768:PgGzpDryv0TQkKb7HGNj43YSEa0LuTMVZzvtLsI+G2TCyqA21Ai:4GFvy1ZYOTTMbts3CPA21Ai - TLSH:
T1F0329EF350A7ED8C7A87EF83ADB51559A489D74D7132A26040C87A7D81BC6FE6F40810 - Submitted as: 01e60.pdf
- File type: pdf · Size: 43270 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=agentes%20contaminantes%20fisicos%20pdf, https://uploads.strikinglycdn.com/files/f975ed3d-97e8-4fca-b5f9-277e822ed62e/47860364982.pdf, https://cdn-cms.f-static.net/uploads/4410985/normal_5f959561ab52f.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=agentes%20contaminantes%20fisicos%20pdf
- https://uploads.strikinglycdn.com/files/f975ed3d-97e8-4fca-b5f9-277e822ed62e/47860364982.pdf
- https://cdn-cms.f-static.net/uploads/4410985/normal_5f959561ab52f.pdf
- https://kivuligob.weebly.com/uploads/1/3/0/8/130874143/493983.pdf
- https://cdn-cms.f-static.net/uploads/4372972/normal_5f8db1d323c03.pdf
- https://uploads.strikinglycdn.com/files/1b1c2730-2539-47df-8bf7-b4e510ae919c/pepari.pdf
- https://uploads.strikinglycdn.com/files/1b6051bc-1b3e-4fda-a0b0-fcb6a0ec8cfd/lg_sj4_review.pdf
- https://sisodiwitamusoz.weebly.com/uploads/1/3/2/6/132681746/zidilud_dogitozejawo_vigematerajope_rulovibudojes.pdf
- https://s3.amazonaws.com/gitipelut/xafemixirinelegu.pdf
- https://cdn-cms.f-static.net/uploads/4378831/normal_5f98a454a7587.pdf
- https://s3.amazonaws.com/genedesowul/xurazodijegopavimi.pdf
- https://uploads.strikinglycdn.com/files/373ed830-1754-4a52-8358-37ad17bd6c11/jogijozazam.pdf
- https://uploads.strikinglycdn.com/files/6ae98325-2b01-4d2a-9061-e538beb6e3d0/38046371106.pdf
- https://bipinutafo.weebly.com/uploads/1/3/4/3/134358532/donanavupag.pdf
- https://s3.amazonaws.com/fosalizuzu/autocad_3d_modeling_exercises.pdf
- https://uploads.strikinglycdn.com/files/4c39dcb8-12d0-4542-9e39-adac8a1777cd/mafutami.pdf
- https://sudateneturoxa.weebly.com/uploads/1/3/4/3/134322726/9011867.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- kivuligob.weebly.com
- sisodiwitamusoz.weebly.com
- s3.amazonaws.com
- bipinutafo.weebly.com
- sudateneturoxa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report