SUSPICIOUS — 1107450871.pdf
SUSPICIOUS — 1107450871.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
a2d8add8a0fcb2b0e7821a47a42d0956a7a09a91a22123faafd9bb8f6df23edf - SHA-1:
6e00697bf3289097c52e0b6a4755105a1efb19c6 - MD5:
fa87b71f0341f1d6ef587252c4bde327 - ssdeep:
768:zgGzpDmkBy1YVHgZBC9SltG3Cf84UpIKoCMWVXJa3W5Hha6Zoae6fvDIWNsPnOG4:MGFaFaZgW5Hw0DIWNsPnOG4 - TLSH:
T14C32AEF321A7ED4C3D469B4369E21599644AD289B273A76008DC772CC5B82EEBF40D60 - Submitted as: 1107450871.pdf
- File type: pdf · Size: 44906 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=meio+ambiente+no+brasil+pdf, https://cdn.shopify.com/s/files/1/0430/1353/7951/files/nissan_leaf_extended_range.pdf, https://cdn.shopify.com/s/files/1/0431/0899/1140/files/kezoludivijopujewemasu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=meio+ambiente+no+brasil+pdf
- https://cdn.shopify.com/s/files/1/0430/1353/7951/files/nissan_leaf_extended_range.pdf
- https://cdn.shopify.com/s/files/1/0431/0899/1140/files/kezoludivijopujewemasu.pdf
- https://cdn.shopify.com/s/files/1/0440/5025/1941/files/94415969138.pdf
- https://cdn.shopify.com/s/files/1/0428/7997/5591/files/latex_homework_template_github.pdf
- http://files.anna4animals.net/uploads/1/3/2/6/132695321/kadiwa.pdf
- http://purevipo.mpflowergarden.com/uploads/1/3/0/8/130813755/webotak.pdf
- http://files.nwcapitalconnection.com/uploads/1/3/0/8/130813818/vukumiridunipavekeg.pdf
- http://ninezuw.ilive4him.org/uploads/1/3/1/4/131407406/9914291.pdf
- http://zudixa.smyrnafoundation.com/uploads/1/3/1/4/131453501/6c7bc4e8.pdf
- https://uploads.strikinglycdn.com/files/e381d0c7-42f5-43b3-8454-bf0d3abd4e3c/29900650168.pdf
- https://uploads.strikinglycdn.com/files/c0adfb29-caad-4dcc-a802-7a859c224ac9/15792272558.pdf
- https://uploads.strikinglycdn.com/files/a1a2dab3-4378-41a0-ada0-001198e057a6/nidenitanibonevazune.pdf
- https://uploads.strikinglycdn.com/files/f985d9e0-94be-412a-b485-fca68020e769/41166205135.pdf
- https://cdn.shopify.com/s/files/1/0463/1409/4749/files/sagaxotoxolofoseni.pdf
- https://cdn.shopify.com/s/files/1/0434/5026/9849/files/architecture_portfolio_samples_free.pdf
- https://cdn.shopify.com/s/files/1/0429/6045/3785/files/dubalevonafa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- files.anna4animals.net
- purevipo.mpflowergarden.com
- files.nwcapitalconnection.com
- ninezuw.ilive4him.org
- zudixa.smyrnafoundation.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report