SUSPICIOUS — ribidir.pdf
SUSPICIOUS — ribidir.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
c6460a2e39580171fa8cfd6ad57416363e90665586948534564046c7503d6546 - SHA-1:
82a471e2892c3a14c0128b00223e9fcf3b60b605 - MD5:
2d691e12bb0939bf583712d735842cee - ssdeep:
768:HgGzpDfpykBxiuBE9EPo7TdB6Gj72O7vy1OOlpWQiGRlNO9F9:AGFDppqTdB//vaTlxRbO9F9 - TLSH:
T12632BFF3106BDD88298BAB836DF602697106C68C3236936055DC2B5DC8BC5FD6F11EA1 - Submitted as: ribidir.pdf
- File type: pdf · Size: 45940 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=el+libro+de+jade+pdf+descargar+grati, http://files.bellido4.com/uploads/1/3/2/6/132681824/robedojozofarada.pdf, http://files.natmanskopf.com/uploads/1/3/0/9/130969204/7467932.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=el+libro+de+jade+pdf+descargar+grati
- http://files.bellido4.com/uploads/1/3/2/6/132681824/robedojozofarada.pdf
- http://files.natmanskopf.com/uploads/1/3/0/9/130969204/7467932.pdf
- http://files.kasimreed.org/uploads/1/3/1/8/131858287/roxetemabovufor.pdf
- http://jafabaju.drdmwilson.com/uploads/1/3/1/3/131383746/829a2a13.pdf
- http://bulona.sinfullydeliciousbakingco.com/uploads/1/3/1/4/131453151/37319a0e87ece8c.pdf
- http://waresuj.writing-raven.com/uploads/1/3/1/0/131071063/972f756.pdf
- http://files.derekconstruction.com/uploads/1/3/1/0/131069921/kadivorujunevat-kakasiduj-xubupila-wabopajakop.pdf
- https://uploads.strikinglycdn.com/files/a62fb605-55b6-4a9c-8083-494aa0371f7b/bunofodefazenalada.pdf
- https://uploads.strikinglycdn.com/files/73445cde-738e-40ec-8fab-bf818b5fb93e/82426882353.pdf
- https://site-1038363.mozfiles.com/files/1038363/bonevenakatov.pdf
- https://site-1037276.mozfiles.com/files/1037276/82751894569.pdf
- https://site-1043601.mozfiles.com/files/1043601/47509588858.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- files.bellido4.com
- files.natmanskopf.com
- files.kasimreed.org
- jafabaju.drdmwilson.com
- bulona.sinfullydeliciousbakingco.com
- waresuj.writing-raven.com
- files.derekconstruction.com
- uploads.strikinglycdn.com
- site-1038363.mozfiles.com
- site-1037276.mozfiles.com
- site-1043601.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report