SUSPICIOUS — 69836519541.pdf
SUSPICIOUS — 69836519541.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
86984dd69ad4864f57b5af2d5d137addc3105b18816cd04d0cbe045e3f4a1804 - SHA-1:
4ebd1fcdb3749804733f25a978f909954f684f44 - MD5:
987fb2be4024abde75ec4a5b41a6851d - ssdeep:
1536:hGFypFw3w4OLDyyErvPymiJB6meUiuufJE4n:EFyp+gREvaePFfJ/ - TLSH:
T18C33BFF31197DDCC7A8A6F536EBA1995A14EE28D2123976414C82B7CC0B8BFD6F10910 - Submitted as: 69836519541.pdf
- File type: pdf · Size: 51910 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=audio+technica+ath+m50xbt+wireless, https://site-1037120.mozfiles.com/files/1037120/63539949478.pdf, https://site-1037115.mozfiles.com/files/1037115/gowazojaditalojo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=audio+technica+ath+m50xbt+wireless
- https://site-1037120.mozfiles.com/files/1037120/63539949478.pdf
- https://site-1037115.mozfiles.com/files/1037115/gowazojaditalojo.pdf
- https://site-1036655.mozfiles.com/files/1036655/53970487245.pdf
- https://uploads.strikinglycdn.com/files/7124289d-78c0-414c-9a3d-0ecef50ef765/38774593261.pdf
- https://uploads.strikinglycdn.com/files/c0be0e57-f75d-47c1-a617-850054c8467e/valupaberenokaranomoretez.pdf
- https://uploads.strikinglycdn.com/files/1977e36e-5fb3-470c-a3bf-c3f6bbdb4c05/bokibonakutogubel.pdf
- https://uploads.strikinglycdn.com/files/3248ac66-0a5c-41e8-85ac-73709526af70/37139529720.pdf
- https://uploads.strikinglycdn.com/files/782f8810-a96b-47b8-8cb0-49ee85863849/suzolinozafe.pdf
- https://uploads.strikinglycdn.com/files/99330325-b225-438d-9351-57af4231c53a/56910644894.pdf
- https://uploads.strikinglycdn.com/files/a67a72f0-08b2-44d5-9b26-83da0a981258/51053722766.pdf
- http://febel.biblicalintensives.com/uploads/1/3/1/0/131070289/1618453.pdf
- http://tokik.highwaycitycd.com/uploads/1/3/1/8/131856158/tikerupetuxataguwaro.pdf
- http://pixokeg.cotwholesale.com/uploads/1/3/0/9/130969465/nakavu.pdf
- http://files.checkoutmyrecipes.com/uploads/1/3/0/7/130740050/0f5335d2289fbb.pdf
- http://files.thetorrancecarpetcleaners.com/uploads/1/3/1/3/131381605/6defc5.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1037120.mozfiles.com
- site-1037115.mozfiles.com
- site-1036655.mozfiles.com
- uploads.strikinglycdn.com
- w.se
- febel.biblicalintensives.com
- tokik.highwaycitycd.com
- pixokeg.cotwholesale.com
- files.checkoutmyrecipes.com
- files.thetorrancecarpetcleaners.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report