SUSPICIOUS — 77184987624.pdf
SUSPICIOUS — 77184987624.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
86c82fe7c41b7e89ec6856751a7ceea42a5b8cef7d0ba7e41caae5cd9b1a5ad3 - SHA-1:
350c5ca04c63f562f89010effb3af9b5be31049f - MD5:
bf7e18ab43615df170d01224119c3327 - ssdeep:
768:ZgGzpDLRlgHdXmIgu2ZOz/DyiuFzT1Fm7V3zoN7b5T9CVWzF1v:aGFvsbiJT1Fmh3zo5T9gQF1v - TLSH:
T137317EF34067ED8C7A8AAF076DB711599187CB4C5133ABA14489B72CC5BC6BD7E00A60 - Submitted as: 77184987624.pdf
- File type: pdf · Size: 41657 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=bgc+17+episode+1+watch+online, https://site-1037240.mozfiles.com/files/1037240/50664526628.pdf, https://site-1039528.mozfiles.com/files/1039528/pibopupedo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=bgc+17+episode+1+watch+online
- https://site-1037240.mozfiles.com/files/1037240/50664526628.pdf
- https://site-1039528.mozfiles.com/files/1039528/pibopupedo.pdf
- https://site-1043087.mozfiles.com/files/1043087/80147435594.pdf
- https://site-1038772.mozfiles.com/files/1038772/46791304713.pdf
- https://site-1040506.mozfiles.com/files/1040506/99695682548.pdf
- http://files.patriotbandsupport.org/uploads/1/3/0/9/130969851/suxavunobefus-xigosu-simidese-zakibuf.pdf
- http://files.eileenheller.com/uploads/1/3/2/3/132303282/5719e0.pdf
- http://files.uccstj.com/uploads/1/3/1/4/131407067/780f265538135a.pdf
- http://xefezi.chakraspirittarot.com/uploads/1/3/2/3/132303099/4530276.pdf
- http://navuvi.uainsectcollection.com/uploads/1/3/1/0/131070420/tilizo.pdf
- https://cdn.shopify.com/s/files/1/0498/0660/6498/files/50_kg_in_pounds_lbs.pdf
- https://cdn.shopify.com/s/files/1/0431/8081/8581/files/71858823382.pdf
- https://cdn.shopify.com/s/files/1/0428/8066/3715/files/bolukesosuzaduj.pdf
- https://cdn.shopify.com/s/files/1/0496/7717/2889/files/57127907345.pdf
- https://cdn.shopify.com/s/files/1/0484/4122/9470/files/poe_tools_harvest.pdf
- https://cdn.shopify.com/s/files/1/0482/4203/2794/files/48191870025.pdf
- https://cdn.shopify.com/s/files/1/0482/5418/9722/files/auto_gg_mod_1.8.9_curseforge.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1037240.mozfiles.com
- site-1039528.mozfiles.com
- site-1043087.mozfiles.com
- site-1038772.mozfiles.com
- site-1040506.mozfiles.com
- files.patriotbandsupport.org
- files.eileenheller.com
- files.uccstj.com
- xefezi.chakraspirittarot.com
- navuvi.uainsectcollection.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report