SUSPICIOUS — 91213531355.pdf
SUSPICIOUS — 91213531355.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
b96bfd40f0e78f7d3d413baffdb11f25727f91ceb09e49cf0bdf70a8800f284e - SHA-1:
19e2d38b3c4a90599550c2c22fefee64e1666a58 - MD5:
828058ded5ef567c55081ef4ee6667a6 - ssdeep:
1536:0GFi6A9LrB3k0Tg9rIvs8Wm9DaI4P0e1QRGKdHR:BFi6Ed3e5sdLeI47iRGKb - TLSH:
T1AA36D0F3548BCD0C6D879B536CB62484540FC6C97563AAA01AC9B76DC8BC2BDAF20611 - Submitted as: 91213531355.pdf
- File type: pdf · Size: 68441 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=pistola+llama+380+especial, https://uploads.strikinglycdn.com/files/0f2802cd-b1ee-4e7c-bf77-020d54fd7538/48717546695.pdf, https://uploads.strikinglycdn.com/files/3f367ce9-0640-4979-bd1d-25b9fd574e91/25023810676.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=pistola+llama+380+especial
- https://uploads.strikinglycdn.com/files/0f2802cd-b1ee-4e7c-bf77-020d54fd7538/48717546695.pdf
- https://uploads.strikinglycdn.com/files/3f367ce9-0640-4979-bd1d-25b9fd574e91/25023810676.pdf
- https://uploads.strikinglycdn.com/files/d8d6ff60-d980-4fb0-b7c2-d74f499a8c8d/botufafozoxetodipobotev.pdf
- https://uploads.strikinglycdn.com/files/f718bae2-7490-4d82-bcd0-8182ac808296/lekugudidofawubese.pdf
- https://uploads.strikinglycdn.com/files/8706a83c-66fe-4327-80bf-b60716b5d307/50996871619.pdf
- http://files.tarrantscn.org/uploads/1/3/2/8/132814250/805713.pdf
- http://vifudujuv.oakwooddcc.com/uploads/1/3/1/3/131398244/rovizab.pdf
- http://files.oliviasmontessori.com/uploads/1/3/0/9/130969472/5a7ce493.pdf
- https://cdn.shopify.com/s/files/1/0432/4953/3088/files/paren.pdf
- https://cdn.shopify.com/s/files/1/0484/5702/3649/files/kupitekivunidinokim.pdf
- https://cdn.shopify.com/s/files/1/0434/6223/0181/files/85018941376.pdf
- https://cdn.shopify.com/s/files/1/0433/3099/4326/files/little_caesars_erie.pdf
- https://cdn.shopify.com/s/files/1/0435/8357/0078/files/scholastic_scope_the_necklace_quiz_answers.pdf
- http://files.ljhskdill.com/uploads/1/3/1/4/131438692/d648d259699.pdf
- http://files.floydslighthouse.com/uploads/1/3/1/3/131379290/seliroviguw_latakasamibu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- files.tarrantscn.org
- vifudujuv.oakwooddcc.com
- files.oliviasmontessori.com
- cdn.shopify.com
- files.ljhskdill.com
- files.floydslighthouse.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report