SUSPICIOUS — 65278685698.pdf
SUSPICIOUS — 65278685698.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
c95b99681f44473b4753f80eb68191011c9558c082363038db9e799878470dfe - SHA-1:
498148b8e8b44184f028becf50773b0d2d98643e - MD5:
6924e769fd9bfb222e15adf2e69c68a2 - ssdeep:
768:8gGzpDhQ/X8hvJunurnLibbCVDCq2P2ZwvqL00oaLMxZ0lPEfpatWhfI7x:ZGFNQ6fKCVDChP2ZhLpoaTkatWhfI7x - TLSH:
T1AA34BFF310A7CD8C6D83EB436AAB255E544BEB4A613297200988376DC8BC7FC7E50560 - Submitted as: 65278685698.pdf
- File type: pdf · Size: 56743 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=barsa+tulu+full+movie, https://uploads.strikinglycdn.com/files/7e1a0c7f-44cb-43b8-9b8d-dbec7b3c252d/39884100209.pdf, https://uploads.strikinglycdn.com/files/96924858-b9f1-42fe-af1b-1760b005f44c/rigekaregazedilofaki.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=barsa+tulu+full+movie
- https://uploads.strikinglycdn.com/files/7e1a0c7f-44cb-43b8-9b8d-dbec7b3c252d/39884100209.pdf
- https://uploads.strikinglycdn.com/files/96924858-b9f1-42fe-af1b-1760b005f44c/rigekaregazedilofaki.pdf
- https://uploads.strikinglycdn.com/files/a2f7285d-0224-4b8c-b634-7d72bf958a6a/jemepupofamatolumuwuref.pdf
- https://uploads.strikinglycdn.com/files/649ce4f8-cae8-4f70-bbbb-175402ffd0f4/99354832077.pdf
- https://cdn.shopify.com/s/files/1/0484/2399/3496/files/tefuratu.pdf
- https://cdn.shopify.com/s/files/1/0428/5333/5207/files/peluwogafupu.pdf
- https://cdn.shopify.com/s/files/1/0485/2416/5282/files/taweje.pdf
- https://cdn.shopify.com/s/files/1/0484/5810/4986/files/8111899735.pdf
- https://uploads.strikinglycdn.com/files/453bf9ef-4986-4114-93fd-cfd042c6cc9f/xupumopinuzal.pdf
- https://uploads.strikinglycdn.com/files/e6bf4cf0-3e9a-45eb-92a3-51424f404f9d/vetabipunut.pdf
- http://fotexegus.aci-construction.org/uploads/1/3/1/4/131453486/7740ba6a8abad.pdf
- http://files.alzeen.com/uploads/1/3/1/6/131606201/001937.pdf
- http://xiwasa.portsmouthacupuncture.org/uploads/1/3/1/6/131636725/lowakijuni.pdf
- http://ganumo.mscap.org/uploads/1/3/2/6/132682685/dijumifatiwodaduteki.pdf
- http://files.pftsports.com/uploads/1/3/0/8/130874034/8938163.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- fotexegus.aci-construction.org
- files.alzeen.com
- xiwasa.portsmouthacupuncture.org
- ganumo.mscap.org
- files.pftsports.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report