SUSPICIOUS — 37474257581.pdf
SUSPICIOUS — 37474257581.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
b85d196fd51ec5bd971764053d71042f13aa92c5d685cf8be62d20297f214aa2 - SHA-1:
5bd083056d2db8c2aa9155a85ca6d0ae742ebaa9 - MD5:
e02d2327c0f819cfa1d6e6ab69242fab - ssdeep:
384:QsFlS3K6XgKV7cAgdOpW+0coZs/5ZIG2sknAwg6MpmGdEJrtx36nsSDtkG8CUSuV:ggGzpDroEfk7nIrs0EvdM5uIVC2Ev - TLSH:
T170308DF75053ED4C7A8A6713BEA61058608AE68DB133E7A054C9772DC4B83FC7E05A60 - Submitted as: 37474257581.pdf
- File type: pdf · Size: 36173 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=examen+ser+bachiller+2019+pdf+resuelto, https://uploads.strikinglycdn.com/files/0e0d087f-4a52-4a32-8a66-a3cbf1062275/17865559402.pdf, https://uploads.strikinglycdn.com/files/418cccae-47c6-4286-b43c-2e0209d2664d/noxaxixovu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=examen+ser+bachiller+2019+pdf+resuelto
- https://uploads.strikinglycdn.com/files/0e0d087f-4a52-4a32-8a66-a3cbf1062275/17865559402.pdf
- https://uploads.strikinglycdn.com/files/418cccae-47c6-4286-b43c-2e0209d2664d/noxaxixovu.pdf
- https://uploads.strikinglycdn.com/files/2f45e4a7-48ce-4467-99db-be06c5c6017a/lekilutatogilufu.pdf
- https://uploads.strikinglycdn.com/files/17c0de1c-8689-44f5-8120-7011a985f8b1/3450990731.pdf
- https://uploads.strikinglycdn.com/files/a5d68b1c-af74-4d09-a828-a9abcad8023c/gutexibim.pdf
- https://uploads.strikinglycdn.com/files/f77e602b-3d98-42e2-8d4f-4105387d16a2/wovuwuwokivevakulediz.pdf
- https://site-1039806.mozfiles.com/files/1039806/82970277859.pdf
- https://site-1038864.mozfiles.com/files/1038864/24389323645.pdf
- http://sugerenu.learningthroughyearning.com/uploads/1/3/1/0/131071258/b56d8de44.pdf
- http://files.budgetmaintenance.net/uploads/1/3/1/4/131437859/5214660.pdf
- http://files.yellowsneakers.com.au/uploads/1/3/2/3/132302984/wuzezogexiguxur-kovebesavika-solinebo-vadunovoga.pdf
- http://files.widebaymotorcomplex.com/uploads/1/3/1/4/131453436/6906728.pdf
- http://momodevoj.sotvpreschool.com/uploads/1/3/0/9/130969723/661038.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1039806.mozfiles.com
- site-1038864.mozfiles.com
- sugerenu.learningthroughyearning.com
- files.budgetmaintenance.net
- files.yellowsneakers.com.au
- files.widebaymotorcomplex.com
- momodevoj.sotvpreschool.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report