SUSPICIOUS — 69464942858.pdf
SUSPICIOUS — 69464942858.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
be3d0909ec8895193e744ea022759deb738295be49e62ec181686a4ff96896b9 - SHA-1:
79bc7fb5f7737c7098833384d106670acbf46e34 - MD5:
34e22dbc630eabec94cbb0755454e2ec - ssdeep:
768:8gGzpDAeW7pDh75viInVBNh9PdlAgRySkeWlE822R6rVcJMj1iIKd5jHWrtb/6n6:ZGFEekVlAgRySMlEbj1JK7zWhb/9AYxX - TLSH:
T1D0326BF350A7EE4C7A87DB03ADAB25699149DA486133EB6045C8772CC47C7BE6F40920 - Submitted as: 69464942858.pdf
- File type: pdf · Size: 45241 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=they+call+me+the+breeze+lyrics, https://cdn-cms.f-static.net/uploads/4366057/normal_5f870b78534dc.pdf, https://cdn-cms.f-static.net/uploads/4366007/normal_5f875a101be42.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=they+call+me+the+breeze+lyrics
- https://cdn-cms.f-static.net/uploads/4366057/normal_5f870b78534dc.pdf
- https://cdn-cms.f-static.net/uploads/4366007/normal_5f875a101be42.pdf
- https://cdn-cms.f-static.net/uploads/4366057/normal_5f86f5af2306c.pdf
- https://cdn-cms.f-static.net/uploads/4369158/normal_5f885a5982430.pdf
- https://cdn-cms.f-static.net/uploads/4368250/normal_5f87b56160d3a.pdf
- https://cdn-cms.f-static.net/uploads/4376099/normal_5f89cbaa09392.pdf
- https://cdn-cms.f-static.net/uploads/4369659/normal_5f88b86e221ea.pdf
- https://cdn-cms.f-static.net/uploads/4372972/normal_5f8947c55116a.pdf
- https://cdn-cms.f-static.net/uploads/4366331/normal_5f88f8d24a829.pdf
- https://cdn-cms.f-static.net/uploads/4365619/normal_5f878b4cb4603.pdf
- https://uploads.strikinglycdn.com/files/7ede1434-8eb3-43c9-8d07-9b0005c2e0bb/tifopaxeverobiloveni.pdf
- https://uploads.strikinglycdn.com/files/986cf9b9-b358-4796-8910-e7d841515edd/betizo.pdf
- https://uploads.strikinglycdn.com/files/2b7d022d-c229-4c31-98d8-6ac4663eaef6/dowemozevizitudabeta.pdf
- https://cdn.shopify.com/s/files/1/0486/5779/3192/files/ninjago_shadow_of_ronin_codes.pdf
- https://cdn.shopify.com/s/files/1/0428/2574/4540/files/lovukeredovulorikoxavot.pdf
- https://cdn.shopify.com/s/files/1/0485/0489/7691/files/can_crabs_have_hearts.pdf
- https://cdn.shopify.com/s/files/1/0427/9864/5404/files/58916343678.pdf
- https://cdn.shopify.com/s/files/1/0504/6186/8192/files/nalilezikunosagu.pdf
- https://cdn.shopify.com/s/files/1/0434/2625/0917/files/taradiserekigazif.pdf
- https://cdn.shopify.com/s/files/1/0493/5640/6940/files/24846952665.pdf
- https://cdn.shopify.com/s/files/1/0482/9800/0539/files/33260320509.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report