SUSPICIOUS — once_upon_a_time_in_venice_torrent.pdf
SUSPICIOUS — once_upon_a_time_in_venice_torrent.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
a3563e609b45495181eb4ac14dae16602c790c64cc4fc97b88bb82cf4ecc89ac - SHA-1:
2a09c835f45b2b61693595617f1e21587fb3e9fe - MD5:
6767e7292ccde2914e458836f0c128e1 - ssdeep:
768:jgGzpD8pCB4+mLOYAOxVEK1sxqi37aI4eFiQBFrA7xcdLxTHXGqqN+NK:cGF4pekGK1nzGFikFrA7xcdtT2T+NK - TLSH:
T1C5327DF358EBDC8C798B9743ACAB1669114AC38CA13ADB5055CC632DD0BC6BD7E10860 - Submitted as: once_upon_a_time_in_venice_torrent.pdf
- File type: pdf · Size: 44281 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=once+upon+a+time+in+venice+torrent, https://uploads.strikinglycdn.com/files/38803070-b5ce-452f-bfa9-3bdcfae8289e/73532866417.pdf, https://uploads.strikinglycdn.com/files/a75a4c30-0819-48c2-b142-f7048614fc2e/59898461249.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=once+upon+a+time+in+venice+torrent
- https://uploads.strikinglycdn.com/files/38803070-b5ce-452f-bfa9-3bdcfae8289e/73532866417.pdf
- https://uploads.strikinglycdn.com/files/a75a4c30-0819-48c2-b142-f7048614fc2e/59898461249.pdf
- https://uploads.strikinglycdn.com/files/b0576c31-c0ee-48e9-a3d1-368555b6696b/pamojuguzulizefatozi.pdf
- https://uploads.strikinglycdn.com/files/5e26eb03-6928-46f7-b21b-4fb4f8f9121f/3672459674.pdf
- https://uploads.strikinglycdn.com/files/f61ea552-e4bd-4d71-bab5-ea8ec598cd11/13866001542.pdf
- https://uploads.strikinglycdn.com/files/200a9406-dd40-4d64-b30a-42873d020add/32552033486.pdf
- https://uploads.strikinglycdn.com/files/86b58712-8d2c-4354-a4b1-9ddd0784a0c9/fo4_unique_player.pdf
- https://uploads.strikinglycdn.com/files/9828453f-75bc-4c48-96c2-44b5a4cee24b/jipakulafidopopesareneje.pdf
- https://uploads.strikinglycdn.com/files/bc1ad756-40ef-4c78-8f9d-b862b060e55c/xosepakema.pdf
- https://uploads.strikinglycdn.com/files/d4dec421-ee5c-44fc-99ab-a3962e675e17/kevikurogujelukuloro.pdf
- https://uploads.strikinglycdn.com/files/37703e4e-7ee0-43b8-a258-c5baad557528/limurerubaledif.pdf
- https://uploads.strikinglycdn.com/files/b8669092-289e-4f28-9bb4-0af10ffe7ec8/zijopewumumobinapadumawi.pdf
- https://xumogimunosu.weebly.com/uploads/1/3/1/6/131607683/bododuxesotifi-wobavenizegu-doloku-pusodud.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/nipomomuka_gisotufeje.pdf
- https://tarirubawapub.weebly.com/uploads/1/3/1/6/131606173/sigunis.pdf
- https://kanudepu.weebly.com/uploads/1/3/2/7/132740929/6165e24.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/bewoti.pdf
- https://uploads.strikinglycdn.com/files/8f963922-a56b-433a-a26a-28d02c60d595/7602460350.pdf
- https://uploads.strikinglycdn.com/files/90dbc76b-07e5-48d2-8a2e-ff838d6deaf5/92163074020.pdf
- https://cdn-cms.f-static.net/uploads/4377381/normal_5f89e55383fd4.pdf
- https://cdn-cms.f-static.net/uploads/4369328/normal_5f8844bc0ee1a.pdf
- https://cdn-cms.f-static.net/uploads/4367005/normal_5f87f1fdbc8b4.pdf
- https://cdn-cms.f-static.net/uploads/4368242/normal_5f87838975d78.pdf
- https://cdn-cms.f-static.net/uploads/4366008/normal_5f87ddd73a7c3.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- xumogimunosu.weebly.com
- jakedekokobara.weebly.com
- tarirubawapub.weebly.com
- kanudepu.weebly.com
- vuxozajuje.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report