SUSPICIOUS — 40994040907.pdf
SUSPICIOUS — 40994040907.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
b35047841e25367626f4e134bfad7de748c778e89a2ea87d9cc4cd692eb3ca02 - SHA-1:
b19a674030dfde64998a4675c279743fdba6792d - MD5:
5522ad42cfe2150235ce8fe14b0bf56f - ssdeep:
1536:ZGFmpnyMoEmg2BMM653YTZMxH7Z4U/s2wVYWeuino5:sFmpyMoE6BMl3YTZMl7Z4U/sBV8W - TLSH:
T12D34ADF310A7DD8CB68BAB47ADA60558604AC78C31278790418C7B2DD8BC6FE7F11A51 - Submitted as: 40994040907.pdf
- File type: pdf · Size: 53332 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=dorian+gray%2527in+portresi+i%25C5%259F+bankas%25C4%25B1+pdf, http://juloj.northeasthamilton.org/uploads/1/3/1/3/131398164/wuvujef.pdf, http://papapibe.safeswitchelectrical.co.uk/uploads/1/3/2/8/132815015/d84b6ba2d964ded.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=dorian+gray%2527in+portresi+i%25C5%259F+bankas%25C4%25B1+pdf
- http://juloj.northeasthamilton.org/uploads/1/3/1/3/131398164/wuvujef.pdf
- http://papapibe.safeswitchelectrical.co.uk/uploads/1/3/2/8/132815015/d84b6ba2d964ded.pdf
- http://files.openchristmasgreatyarmouth.org/uploads/1/3/1/4/131412032/xonimawifitar.pdf
- http://files.myfmadvertising.com/uploads/1/3/2/7/132740384/6033365.pdf
- http://files.katelynswart.com/uploads/1/3/1/0/131070355/wepekaviwom.pdf
- https://uploads.strikinglycdn.com/files/5356388f-fa2e-4948-8590-4738c3b2966c/24325812229.pdf
- https://uploads.strikinglycdn.com/files/d71eabcf-7d14-46fb-bf7a-3beedccd4c34/rokisizis.pdf
- https://uploads.strikinglycdn.com/files/47d8657f-1012-49ab-8b75-b2d001c0f475/99623636682.pdf
- https://uploads.strikinglycdn.com/files/08840378-691b-4cce-9247-d2850a18d0d9/54346938266.pdf
- https://uploads.strikinglycdn.com/files/20ed6ee6-5387-435e-b27c-7f9afa27d27e/68205510586.pdf
- https://uploads.strikinglycdn.com/files/08eeadcb-0dbc-47b5-9564-ad0643cd94ad/mitikalifuvadume.pdf
- https://uploads.strikinglycdn.com/files/b0dbbf7d-0f25-4686-a9e3-504b3370a5d5/zolaxoriluregijeva.pdf
- https://uploads.strikinglycdn.com/files/fb61301c-cc86-4a81-b576-522082c2e1e1/tagudeginawegiduxolafo.pdf
- https://uploads.strikinglycdn.com/files/43672c2f-0aa1-4c45-99aa-42a4f7e76ef4/rogepuzigixowakeraperuw.pdf
- https://uploads.strikinglycdn.com/files/90bb2487-e459-4ff3-945f-bee447e5b8d9/xotesirawegemuxogeliv.pdf
- https://uploads.strikinglycdn.com/files/c9f05ea8-3512-4593-a3da-da22d96b86b7/ledaxagonilatoz.pdf
- https://uploads.strikinglycdn.com/files/6ef631cd-eba9-4cf6-b2fd-70dd78540d6f/datemokipiz.pdf
- https://uploads.strikinglycdn.com/files/c7634540-f112-4b9c-b7fd-a51ec7755c2d/nizudafefujexezosesuk.pdf
- https://uploads.strikinglycdn.com/files/ff058630-750f-4045-836a-907d6d73bc21/misenepazutezogoliv.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- juloj.northeasthamilton.org
- papapibe.safeswitchelectrical.co.uk
- files.openchristmasgreatyarmouth.org
- files.myfmadvertising.com
- files.katelynswart.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report