SUSPICIOUS — 94526932969.pdf
SUSPICIOUS — 94526932969.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
d1aa8d410289f2ffa70cd00b2dee9d10cc12ee8b04d8a93e36ccd8f957c7cf01 - SHA-1:
1c3f5b0d63b5b42f0eadc2db5ece6548fb8db6de - MD5:
f2fa3fb59c5cd921e8619d210455bc8c - ssdeep:
1536:JGF9kEK+taCzUZMfc4LJHao92Ow1hJRl:cF9kXsaC2Mfc4L5N92O+ - TLSH:
T1FC339FF35093ED8C7A8BAF079EA7115A648AC74D6533A7905888772CD47CAFC1F00A64 - Submitted as: 94526932969.pdf
- File type: pdf · Size: 49929 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=bike+chain+guide+tensioner, https://cdn-cms.f-static.net/uploads/4369926/normal_5f913d3d1dc44.pdf, https://cdn-cms.f-static.net/uploads/4388162/normal_5f91a82ff41e8.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=bike+chain+guide+tensioner
- https://cdn-cms.f-static.net/uploads/4369926/normal_5f913d3d1dc44.pdf
- https://cdn-cms.f-static.net/uploads/4388162/normal_5f91a82ff41e8.pdf
- https://cdn-cms.f-static.net/uploads/4378836/normal_5f8ccd54a7a5e.pdf
- https://cdn-cms.f-static.net/uploads/4382770/normal_5f8da68c47684.pdf
- https://uploads.strikinglycdn.com/files/f8ad52cf-ea61-49ef-8e24-2db1a7240b77/pazejofutoneviwu.pdf
- https://cdn-cms.f-static.net/uploads/4401985/normal_5f922eb06b373.pdf
- https://cdn-cms.f-static.net/uploads/4386618/normal_5f9083fa09726.pdf
- https://cdn-cms.f-static.net/uploads/4369915/normal_5f91adad69b16.pdf
- https://cdn-cms.f-static.net/uploads/4377662/normal_5f8ce0346e026.pdf
- https://cdn-cms.f-static.net/uploads/4383321/normal_5f8c7ffb20caf.pdf
- https://s3.amazonaws.com/mijedusovineti/95784515755.pdf
- https://s3.amazonaws.com/mijedusovineti/95983949868.pdf
- https://s3.amazonaws.com/subud/piwudelobagula.pdf
- https://s3.amazonaws.com/wizuluworafid/lovolasulamu.pdf
- https://nukubutoti.weebly.com/uploads/1/3/2/3/132302768/79c58012d3eef.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/wogiselaruto-nokage.pdf
- https://uploads.strikinglycdn.com/files/77319ddc-c67c-4c56-b23c-45ed32ae017d/wotoxesesolilu.pdf
- https://uploads.strikinglycdn.com/files/007652fd-b0b3-47a6-83b6-28a73fbacb21/5919399715.pdf
- https://uploads.strikinglycdn.com/files/e6295630-4484-4257-acb0-08be4bb860bb/full_hd_car_dvr_1080p.pdf
- https://uploads.strikinglycdn.com/files/f7382fbd-926a-40f0-8a2c-411eede5d093/28668638145.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- s3.amazonaws.com
- nukubutoti.weebly.com
- xojerajap.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report