SUSPICIOUS — 79966442475.pdf
SUSPICIOUS — 79966442475.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
9cd58470864c397eac58c2e6edc3f94b04c257199809514c74977f3a85558f92 - SHA-1:
47a20cfc9a35972f8afa88f183804e621b4d3701 - MD5:
e6f514e7d1c152ef5158d2b5afe69465 - ssdeep:
768:VgGzpDMW7IEyCGBxSTAySF1omvDlCDByDw6HXx+KZDDhetWsc4M0dX9dKB2l9OT4:GGFgCY8AymemvDWkHAuAtWOpdX9dKB2Z - TLSH:
T10A317DF340E7EC8C6EC69B03ADDA245D918AC6886123E67409DCB76CD47C2BD7E01960 - Submitted as: 79966442475.pdf
- File type: pdf · Size: 42867 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=kaufland+buduci+letak+pdf, https://cdn.shopify.com/s/files/1/0454/7385/7686/files/lotuburobapima.pdf, https://cdn.shopify.com/s/files/1/0431/8494/7357/files/gitlab_tutorial_for_beginners.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=kaufland+buduci+letak+pdf
- https://cdn.shopify.com/s/files/1/0454/7385/7686/files/lotuburobapima.pdf
- https://cdn.shopify.com/s/files/1/0431/8494/7357/files/gitlab_tutorial_for_beginners.pdf
- https://cdn.shopify.com/s/files/1/0432/6490/1284/files/18516417766.pdf
- https://cdn.shopify.com/s/files/1/0433/5281/7832/files/gerivulorizekojufubujomew.pdf
- http://kuvore.1stvoice.com/uploads/1/3/0/7/130775200/vivobitutixa_doxuli_batugedutu_kobavulozulese.pdf
- http://files.bromleyfriendsforum.org/uploads/1/3/0/7/130775145/5894322.pdf
- http://files.evanchambers.net/uploads/1/3/0/7/130775033/50b859c85.pdf
- http://zutigifa.lighthouseontheprairie.com/uploads/1/3/2/7/132740873/dasibipogegoxareb.pdf
- http://vowoxeva.southdevonslinglibrary.com/uploads/1/3/2/7/132740267/feratasupa-savepaxifikano-rusipuzit-kepazeve.pdf
- http://files.mccoyagency.com/uploads/1/3/1/8/131872054/5927881.pdf
- http://files.exetermindfulnesswelcome.com/uploads/1/3/0/8/130814411/5e89076.pdf
- http://vaxur.delorisartist.com/uploads/1/3/1/6/131636698/dipemewomamu.pdf
- http://files.bigmamasugarcookies.com/uploads/1/3/0/7/130740262/9a2f2840893.pdf
- http://files.elladavidson.com/uploads/1/3/1/4/131454024/nasivexezapew.pdf
- http://fuwevowi.cabezonmastiffs.net/uploads/1/3/1/3/131379373/b20229b8c1e6caf.pdf
- http://dovajetiw.moraira-holidayvillas.com/uploads/1/3/0/8/130813632/nidorozapevu.pdf
- http://files.lab302.net/uploads/1/3/1/8/131871535/xoxonizoguwuw-vasexaboxukil.pdf
- http://dezen.poco-jh.com/uploads/1/3/0/7/130739811/vomazawomere.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- kuvore.1stvoice.com
- files.bromleyfriendsforum.org
- files.evanchambers.net
- zutigifa.lighthouseontheprairie.com
- vowoxeva.southdevonslinglibrary.com
- files.mccoyagency.com
- files.exetermindfulnesswelcome.com
- vaxur.delorisartist.com
- files.bigmamasugarcookies.com
- files.elladavidson.com
- fuwevowi.cabezonmastiffs.net
- dovajetiw.moraira-holidayvillas.com
- files.lab302.net
- dezen.poco-jh.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report