SUSPICIOUS — 8293196545.pdf
SUSPICIOUS — 8293196545.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
d4b53d8e90c97ad98d266f26cb87cd12f17c5938f3172cde177fc96ada7d14d9 - SHA-1:
d762ff91daa4ce62fcf7984fe0270d2bf2db6762 - MD5:
c0e0178af67953875fb06d9e1d88fb40 - ssdeep:
768:FgGzpDLntvBXIpYSs4vVlB86kClLLZBxYjWdRziUgeUHPGMVBou:WGFvnHIpXscbi6k6tBKadReUG1Bou - TLSH:
T1EA34AEF758A7EECCBAC76B17AAE61494910AD3896133D3A4048C336CC47C6BD7E54821 - Submitted as: 8293196545.pdf
- File type: pdf · Size: 53278 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=the+cherry+tree+by+ruskin+bond+pdf+free+download, https://uploads.strikinglycdn.com/files/18adb8e5-9c7e-4d08-945a-5094b5d86a2f/vonotewajujerofakefok.pdf, https://uploads.strikinglycdn.com/files/a900deee-f0cc-4d97-9392-d4684ad43a7a/finuxepu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=the+cherry+tree+by+ruskin+bond+pdf+free+download
- https://uploads.strikinglycdn.com/files/18adb8e5-9c7e-4d08-945a-5094b5d86a2f/vonotewajujerofakefok.pdf
- https://uploads.strikinglycdn.com/files/a900deee-f0cc-4d97-9392-d4684ad43a7a/finuxepu.pdf
- https://uploads.strikinglycdn.com/files/7188f296-f93c-4ee0-8ffd-43198aa8ee4b/gugivovebinupaniwi.pdf
- https://uploads.strikinglycdn.com/files/4bb3d673-38b4-4e29-aa10-6a5a531f6e2f/pexerejefuzazi.pdf
- https://uploads.strikinglycdn.com/files/6c5573df-6e98-4098-9648-9ed11aa56e1a/56031494811.pdf
- https://site-1037916.mozfiles.com/files/1037916/setonilizogofenajobatala.pdf
- https://site-1036719.mozfiles.com/files/1036719/pexoto.pdf
- https://site-1037829.mozfiles.com/files/1037829/90932301357.pdf
- https://site-1037276.mozfiles.com/files/1037276/48560879004.pdf
- https://site-1037061.mozfiles.com/files/1037061/kolupokatow.pdf
- https://uploads.strikinglycdn.com/files/6642f640-7273-484f-a639-718eb8e552f6/93506059309.pdf
- https://uploads.strikinglycdn.com/files/71cd7ae8-9c36-4d31-ad5c-76163d9bca89/43377280843.pdf
- https://uploads.strikinglycdn.com/files/5e806ad4-049d-4ad8-87ae-36f10af8799c/lupitemerivemado.pdf
- https://uploads.strikinglycdn.com/files/a365b764-0e66-4e7a-ba71-98398eefb7b2/12106342302.pdf
- http://durutoni.conseilscolaire-schoolcouncil.com/uploads/1/3/1/0/131070356/rekemar-pijinebujudoduk.pdf
- http://nokon.renuent.com/uploads/1/3/2/6/132680813/debodedumug.pdf
- http://files.bassettcreek.us/uploads/1/3/1/4/131438741/fujemejab.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1037916.mozfiles.com
- site-1036719.mozfiles.com
- site-1037829.mozfiles.com
- site-1037276.mozfiles.com
- site-1037061.mozfiles.com
- durutoni.conseilscolaire-schoolcouncil.com
- nokon.renuent.com
- files.bassettcreek.us
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report