SUSPICIOUS — 22833927479.pdf
SUSPICIOUS — 22833927479.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
acd9ca6ae7af1227de60f24becbdefc33ca533321523682f39491607807efc44 - SHA-1:
ec92375d322cba863e0ebadc5303da0a3c1cfbac - MD5:
6376a69e98560b5803ecc0e6520adfb4 - ssdeep:
768:xgGzpDkvRipai30HcVahwy7YRQ26CuYRaM7g7ZE6ijaGn/jikJ8myScSw:CGFAv98Qh7YRr6CukOJieG/jrJ8b3Sw - TLSH:
T1A732BEF3509BED4878C75B43A8D61169118AC34C72339AB049D8BB6CC97C6BEBF01961 - Submitted as: 22833927479.pdf
- File type: pdf · Size: 45701 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=assainissement+pdf+cours, http://zafupu.christinaangelafisher.com/uploads/1/3/1/4/131406453/41725a0811.pdf, http://files.mylenebaxterconsulting.com/uploads/1/3/0/7/130740517/demux_nafiwiwi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=assainissement+pdf+cours
- http://zafupu.christinaangelafisher.com/uploads/1/3/1/4/131406453/41725a0811.pdf
- http://files.mylenebaxterconsulting.com/uploads/1/3/0/7/130740517/demux_nafiwiwi.pdf
- http://tafufalun.helloshannonlee.com/uploads/1/3/0/7/130775075/854526acc795.pdf
- http://files.beatricestravelingboutique.com/uploads/1/3/2/6/132696465/3292483.pdf
- http://murazim.peggyjoyceruth.org/uploads/1/3/0/7/130775607/kuvawif.pdf
- http://fegumonoj.offlinecrypto.us/uploads/1/3/1/4/131438392/562e12a8938.pdf
- http://nebebot.backtwo.us/uploads/1/3/1/4/131452846/gibegi.pdf
- https://cdn.shopify.com/s/files/1/0483/5019/9961/files/jimatudadenida.pdf
- https://cdn.shopify.com/s/files/1/0435/2340/8032/files/81759442968.pdf
- https://cdn.shopify.com/s/files/1/0433/4059/5352/files/positive_affirmations_for_mental_health.pdf
- https://site-1036839.mozfiles.com/files/1036839/25942290736.pdf
- https://site-1036628.mozfiles.com/files/1036628/72206327756.pdf
- https://site-1037048.mozfiles.com/files/1037048/jogevadajolavab.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- zafupu.christinaangelafisher.com
- files.mylenebaxterconsulting.com
- tafufalun.helloshannonlee.com
- files.beatricestravelingboutique.com
- murazim.peggyjoyceruth.org
- fegumonoj.offlinecrypto.us
- nebebot.backtwo.us
- cdn.shopify.com
- site-1036839.mozfiles.com
- site-1036628.mozfiles.com
- site-1037048.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report