SUSPICIOUS — 99910344189.pdf
SUSPICIOUS — 99910344189.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
c4eade68ec24333afc73ee4396e52a53d990dda35e951ac0d89f8c569157d0ba - SHA-1:
b7231c5cc893d3e5a79d1bb403f0b2fb59e77dbe - MD5:
63aaef034b0064fa114d9080223fecb3 - ssdeep:
768:QgGzpDRp8lhxiCVbl9i+S1yCkhLhhU6LXIgA49+qnFEKk2ZXIRXXsH:9GFtpo3rl9i+S8CkK6LXIgWqFEyIRXO - TLSH:
T1D0329DF721A7DD8C7A86A7076DEA1024A646D34C71329794898C376CD4BC6FD7E008B2 - Submitted as: 99910344189.pdf
- File type: pdf · Size: 45162 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=micrometer+screw+gauge+pdf+download, https://site-1043246.mozfiles.com/files/1043246/dulodubetuzoketerilurub.pdf, https://site-1043260.mozfiles.com/files/1043260/22459342828.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=micrometer+screw+gauge+pdf+download
- https://site-1043246.mozfiles.com/files/1043246/dulodubetuzoketerilurub.pdf
- https://site-1043260.mozfiles.com/files/1043260/22459342828.pdf
- https://site-1044312.mozfiles.com/files/1044312/juxodanamofib.pdf
- https://site-1036630.mozfiles.com/files/1036630/rorigadibubopad.pdf
- https://uploads.strikinglycdn.com/files/1b7c1eb0-0745-416d-8703-5ff9343c3c27/roxituzexe.pdf
- https://uploads.strikinglycdn.com/files/ca0737ab-1eac-44d7-9bd4-0578c910b480/marobudisu.pdf
- https://uploads.strikinglycdn.com/files/2ea0ec0c-0c8b-43af-99ac-99c4b4daf7be/74190401519.pdf
- https://uploads.strikinglycdn.com/files/a20b60e5-be2c-4fe9-8596-52ffd244fe13/87657895975.pdf
- https://uploads.strikinglycdn.com/files/6fb2cea8-a1e4-47ba-9b22-f80a06a10aef/59738782700.pdf
- https://uploads.strikinglycdn.com/files/31ef3963-b5c8-4fc5-905b-979b2bb02ee7/nitofojulugijiwalowelezi.pdf
- https://uploads.strikinglycdn.com/files/435fc3a2-958a-472d-af4e-715eee99a6ba/34538198736.pdf
- https://cdn.shopify.com/s/files/1/0495/5475/1648/files/death_is_nothing_at_all_analysis.pdf
- https://cdn.shopify.com/s/files/1/0498/7810/6270/files/45055546857.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1043246.mozfiles.com
- site-1043260.mozfiles.com
- site-1044312.mozfiles.com
- site-1036630.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report