SUSPICIOUS — 5979267305.pdf
SUSPICIOUS — 5979267305.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
af13dfcd89f7a09f1bf204cfbecc3c091003166b3da59ba1cb5abfae23987c0c - SHA-1:
3639b18f3e0da0ff45737ddbbf3649835ccb43d9 - MD5:
126a79ed9e04026187d779620c9fb704 - ssdeep:
768:sgGzpDJ2FLcwy3p2nZQKQU0MsiQzF958Ibz9vqg2cMvnFWf8gO7qTyGdx9:pGF9j2ZVFAiQ5jBbnMfFWf8REx9 - TLSH:
T11B339EF34163DD8CBA8BDF136DE62468A04AD68831B2D76049D5763CC47C7BCAE05A21 - Submitted as: 5979267305.pdf
- File type: pdf · Size: 51311 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=surgical+anatomy+of+pancreas+pdf, http://files.shangrilavintage.com/uploads/1/3/1/8/131857983/911682.pdf, http://files.thetailgatist.com/uploads/1/3/2/6/132695633/jamigagiviwepe-savinizuduzij.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=surgical+anatomy+of+pancreas+pdf
- http://files.shangrilavintage.com/uploads/1/3/1/8/131857983/911682.pdf
- http://files.thetailgatist.com/uploads/1/3/2/6/132695633/jamigagiviwepe-savinizuduzij.pdf
- http://files.sharonviewcorpcenter.com/uploads/1/3/2/6/132695472/24611465.pdf
- http://xuxudujej.shupik.com/uploads/1/3/2/6/132682892/lufofukumomataz_gufasug_lovaz_sawik.pdf
- http://files.apexespta.com/uploads/1/3/2/3/132302966/womajisujipa_nopikami_konozibibusup.pdf
- http://xulor.agoodnightssleep.net/uploads/1/3/1/3/131382133/b4662f.pdf
- http://jidikus.mztext.com/uploads/1/3/0/8/130873872/kagom.pdf
- http://files.suzanneahmet.com/uploads/1/3/0/9/130969045/zubigavilanexejo.pdf
- https://site-1039783.mozfiles.com/files/1039783/genumonefopede.pdf
- https://site-1036950.mozfiles.com/files/1036950/10501563271.pdf
- https://site-1036898.mozfiles.com/files/1036898/22854225379.pdf
- https://site-1036627.mozfiles.com/files/1036627/ludivi.pdf
- https://uploads.strikinglycdn.com/files/339b1ffa-dc64-445d-8105-7da61a903e4d/nalidi.pdf
- https://uploads.strikinglycdn.com/files/c695991e-589e-4363-984c-7cf6b4a46e82/bagufuguvup.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- files.shangrilavintage.com
- files.thetailgatist.com
- files.sharonviewcorpcenter.com
- xuxudujej.shupik.com
- files.apexespta.com
- xulor.agoodnightssleep.net
- jidikus.mztext.com
- files.suzanneahmet.com
- site-1039783.mozfiles.com
- site-1036950.mozfiles.com
- site-1036898.mozfiles.com
- site-1036627.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report