SUSPICIOUS — 9718471.pdf
SUSPICIOUS — 9718471.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
9b246993cc5d83b821bf205d17aa8c6172024208469297a591746de5b170a8ed - SHA-1:
a4b069cd32fe0bdba4a63ff644dfb9dc0dd91e46 - MD5:
b9e8408abed800858aea9293dd977d5a - ssdeep:
1536:p7/CsyobXgzARCHQYrErbxgOzeR4vxpGchzqVockuO/Kl2m/Xidm:TBXOAQSgNmvPhOVockuAEj - TLSH:
T1ED37D0F3518BDD8C378AAF53A9B71A6CB08AD74C2023D7B05899765EC5B82BD1D40D20 - Submitted as: 9718471.pdf
- File type: pdf · Size: 73072 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=udemy%20python%20course%20videos%20free, https://lixevipilevorox.weebly.com/uploads/1/3/4/6/134634278/6c571.pdf, https://uploads.strikinglycdn.com/files/88022a6f-ee2b-48d3-84a2-e127207cf971/43190242213.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=udemy%20python%20course%20videos%20free
- https://lixevipilevorox.weebly.com/uploads/1/3/4/6/134634278/6c571.pdf
- https://uploads.strikinglycdn.com/files/88022a6f-ee2b-48d3-84a2-e127207cf971/43190242213.pdf
- https://uploads.strikinglycdn.com/files/d4d20d1d-bac0-41a6-b707-2df33efb0c9a/xajebukepegatiziganotip.pdf
- https://cdn-cms.f-static.net/uploads/4447649/normal_5fa62865eb03c.pdf
- https://cdn-cms.f-static.net/uploads/4500429/normal_5fad4db75d8cf.pdf
- https://dudabiwik.weebly.com/uploads/1/3/4/3/134354119/dogewavupu_bakeguvi_womekatexoruki.pdf
- https://wufenimikefi.weebly.com/uploads/1/3/4/3/134366244/fc661f3e9792c.pdf
- https://uploads.strikinglycdn.com/files/96aafa6b-a4fc-4778-8bfb-ee29a4ac1684/30180038147.pdf
- https://bisojobiregabo.weebly.com/uploads/1/3/4/5/134509607/b2e1767f173.pdf
- https://cdn-cms.f-static.net/uploads/4421781/normal_5fad6850ad33a.pdf
- https://cdn-cms.f-static.net/uploads/4426413/normal_5f99369490fe3.pdf
- https://lififamofupuge.weebly.com/uploads/1/3/4/3/134317858/28b645a4183c3.pdf
- https://cdn-cms.f-static.net/uploads/4369491/normal_5fa1c30a0f7c9.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- lixevipilevorox.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- dudabiwik.weebly.com
- wufenimikefi.weebly.com
- bisojobiregabo.weebly.com
- lififamofupuge.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report