SUSPICIOUS — 24035820036.pdf
SUSPICIOUS — 24035820036.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
827b03556d5c5b7f2240a64123a7c4736d6128b41ee26ef09093b4e3f38de327 - SHA-1:
692f495e77e2901b273a61aa46261e91a39e774e - MD5:
30444282a1b93dd806ac6633aba12128 - ssdeep:
768:LgGzpD0l9vN3ca4k+rtZjs6MxnmSlE4ZT6yOeuz4Pnde7N6fQ7HEL1dyOBwP:0GFQl6s6MtBEXyBNkBELbyOBwP - TLSH:
T112329CF3049BED0D7ACB9B036CEA001A654AC3886233E66055DC7B2DD57C6BDBE405A1 - Submitted as: 24035820036.pdf
- File type: pdf · Size: 44920 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=divinity+2+undead+build, https://site-1036832.mozfiles.com/files/1036832/86878612870.pdf, https://site-1037120.mozfiles.com/files/1037120/popunadevin.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=divinity+2+undead+build
- https://site-1036832.mozfiles.com/files/1036832/86878612870.pdf
- https://site-1037120.mozfiles.com/files/1037120/popunadevin.pdf
- https://site-1037028.mozfiles.com/files/1037028/32513217755.pdf
- https://uploads.strikinglycdn.com/files/f73de585-adba-4d90-93fe-f7fb5e0a97d4/73319905496.pdf
- https://uploads.strikinglycdn.com/files/9bc81cb3-3ad8-4347-9d74-a11a4f5e1cb3/21954222035.pdf
- https://uploads.strikinglycdn.com/files/7b110c95-a36f-4c56-a8f3-6b194e699d88/zerapibewugidilepegi.pdf
- https://cdn.shopify.com/s/files/1/0440/5254/5686/files/old_world_blues_ncr_brotherhood_war.pdf
- https://cdn.shopify.com/s/files/1/0465/3921/0911/files/cable_tv_guide_athens_ga.pdf
- https://cdn.shopify.com/s/files/1/0457/3754/1798/files/cell_specialization_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0485/7554/5509/files/vugubowagojasema.pdf
- https://cdn.shopify.com/s/files/1/0433/5304/7195/files/98452883147.pdf
- https://cdn.shopify.com/s/files/1/0430/5387/5357/files/59022055394.pdf
- https://cdn.shopify.com/s/files/1/0428/1961/6935/files/39959729577.pdf
- https://cdn.shopify.com/s/files/1/0486/0542/9928/files/50383886167.pdf
- https://cdn.shopify.com/s/files/1/0430/4352/0666/files/japanese_demystified.pdf
- https://cdn.shopify.com/s/files/1/0478/0136/8743/files/33708158690.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1036832.mozfiles.com
- site-1037120.mozfiles.com
- site-1037028.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report