SUSPICIOUS — livros_de_direito_do_trabalho.pdf
SUSPICIOUS — livros_de_direito_do_trabalho.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
a3ef8ac7efc7bee2b3efa761b795c88db26aa89a1bde4e271da4c14f3cad7f55 - SHA-1:
11b2d9209ad2303b34ece51e30d06670399c399d - MD5:
b32e6c09b94099fd82d57030a6763ef9 - ssdeep:
768:YgGzpDyp2gRyuPYYvDTz4stATJbrdZJj5AOgk7pOPFKmc9StFX89NZWJ0/:1GFOpJ4stubrdLj6OBQdKSX8PZWJ0/ - TLSH:
T18A327DF3509BED4C798BA743ADA712B5108DC3C83236A7A0559C7A2D84BCABD7F50850 - Submitted as: livros_de_direito_do_trabalho.pdf
- File type: pdf · Size: 46467 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=livros+de+direito+do+trabalho+pdf, https://uploads.strikinglycdn.com/files/48cfd1db-6641-4306-a0ad-109605bc9fcf/kuzibozirekoxodomejejig.pdf, https://uploads.strikinglycdn.com/files/c2c8514a-0477-4bad-9a1b-47528ce26225/7895708179.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=livros+de+direito+do+trabalho+pdf
- https://uploads.strikinglycdn.com/files/48cfd1db-6641-4306-a0ad-109605bc9fcf/kuzibozirekoxodomejejig.pdf
- https://uploads.strikinglycdn.com/files/c2c8514a-0477-4bad-9a1b-47528ce26225/7895708179.pdf
- https://uploads.strikinglycdn.com/files/f68f8e4a-4439-41d5-ae6c-9c7f828e841e/57165639550.pdf
- https://uploads.strikinglycdn.com/files/c589770e-a1f2-4d8f-80fa-f933ac2c4a10/zunixujupowabupesekav.pdf
- https://cdn-cms.f-static.net/uploads/4373281/normal_5f89c3bf6866c.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f87e602aba4f.pdf
- https://cdn-cms.f-static.net/uploads/4367017/normal_5f8951ad97d10.pdf
- https://cdn-cms.f-static.net/uploads/4379034/normal_5f8a320f983db.pdf
- https://cdn.shopify.com/s/files/1/0481/6093/1991/files/sadikexepifiveri.pdf
- https://cdn.shopify.com/s/files/1/0488/1858/5765/files/skills_worksheet_directed_reading_a_answers_key_earth_science.pdf
- https://cdn.shopify.com/s/files/1/0432/1558/5448/files/73424605285.pdf
- https://cdn.shopify.com/s/files/1/0497/4660/8282/files/48822158277.pdf
- https://uploads.strikinglycdn.com/files/67b095c4-6821-449b-a1b7-b05e02ed36bf/45873125772.pdf
- https://uploads.strikinglycdn.com/files/1fddce28-2671-4915-b001-ca156b2373e3/jojawo.pdf
- https://uploads.strikinglycdn.com/files/0da8804a-32e9-497a-909d-3ba8b3abe4bc/fukekedemiwizewiwiduf.pdf
- https://uploads.strikinglycdn.com/files/470013a0-7c13-478e-90b7-0f148785b645/nexopuvukijasokobinil.pdf
- https://uploads.strikinglycdn.com/files/1e468e10-e71b-4ff0-b456-455719d7c6b6/14307103817.pdf
- https://uploads.strikinglycdn.com/files/52faf1ca-8977-4a32-823e-d0001c9db1eb/83670649683.pdf
- https://uploads.strikinglycdn.com/files/cfce034b-c647-4e4b-b7f9-2acddab7db87/zurewewalovujudotutukor.pdf
- https://uploads.strikinglycdn.com/files/512087bd-4978-49d5-ba32-f2162f365444/77912501001.pdf
- https://uploads.strikinglycdn.com/files/6ecf8160-efa3-4e19-b847-961dc697f4e3/vositisebelutalofo.pdf
- https://uploads.strikinglycdn.com/files/18f32f0d-17cd-4f66-8c8d-880b35890544/nomonasopinepun.pdf
- https://uploads.strikinglycdn.com/files/7b7fa9f1-c894-4783-b647-4556e03e3b82/34263380629.pdf
- https://uploads.strikinglycdn.com/files/e2134b7c-f6cc-419d-a3e8-043d8334f907/lisemejosedefame.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- nf.tv
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report