SUSPICIOUS — 10118315631.pdf
SUSPICIOUS — 10118315631.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
d53a89636d816993b63617d7d45bc637ad6da1fb949ea58ce69fcbb8b23aec94 - SHA-1:
c215e1fec3f8aebfa9117e2c004f04240c086891 - MD5:
54f78669c35b10daf6e9272b4cc1b145 - ssdeep:
1536:8GFyWHCmR6fov4XimMxVL4JsyES6Bnt+bjAFg:ZFyWimRrvgimSVL4In03T - TLSH:
T148349EF3419BDD8C3A8BBB476EB7104D6046D28970669BA04588772CC4BC6FDBF10A51 - Submitted as: 10118315631.pdf
- File type: pdf · Size: 53672 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=amadis+de+gaula+pdf, https://uploads.strikinglycdn.com/files/65be0921-3862-417b-9bfb-9f6727dbff6d/xikugorusopiwuvoralonu.pdf, https://uploads.strikinglycdn.com/files/97838d92-f810-4ef1-a5e9-0d75b2fca44f/19035165199.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=amadis+de+gaula+pdf
- https://uploads.strikinglycdn.com/files/65be0921-3862-417b-9bfb-9f6727dbff6d/xikugorusopiwuvoralonu.pdf
- https://uploads.strikinglycdn.com/files/97838d92-f810-4ef1-a5e9-0d75b2fca44f/19035165199.pdf
- https://uploads.strikinglycdn.com/files/10d982ca-41a2-4185-bdbf-1192a6119150/fudilexejupuvof.pdf
- https://uploads.strikinglycdn.com/files/a2e4748e-7a97-4ef2-818a-8db3746f5f24/15753458856.pdf
- https://uploads.strikinglycdn.com/files/8e36c536-d7a6-4643-971d-bdaa67838e11/luritow.pdf
- https://site-1036876.mozfiles.com/files/1036876/57528195033.pdf
- https://site-1036764.mozfiles.com/files/1036764/zipimositijozaze.pdf
- https://site-1036649.mozfiles.com/files/1036649/39725892522.pdf
- https://site-1037113.mozfiles.com/files/1037113/tupinufalupame.pdf
- https://site-1037094.mozfiles.com/files/1037094/paxakunezuwitolavake.pdf
- https://site-1036667.mozfiles.com/files/1036667/dadavijagupawetazoj.pdf
- https://site-1036775.mozfiles.com/files/1036775/muduzate.pdf
- https://site-1037130.mozfiles.com/files/1037130/siturasururas.pdf
- https://site-1036779.mozfiles.com/files/1036779/35754335713.pdf
- https://uploads.strikinglycdn.com/files/8626598d-9f90-4695-899e-45c2c37566ae/14267260278.pdf
- https://uploads.strikinglycdn.com/files/7ca2c3f3-ce5e-4a06-a080-78e60ad0cf44/sejumok.pdf
- https://uploads.strikinglycdn.com/files/f1d03880-7c4d-4e37-bba3-39752439d7cf/7117653529.pdf
- https://uploads.strikinglycdn.com/files/5e4798fb-c4e0-44ea-a17e-b8a0cd4be439/bazudawosis.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1036876.mozfiles.com
- site-1036764.mozfiles.com
- site-1036649.mozfiles.com
- site-1037113.mozfiles.com
- site-1037094.mozfiles.com
- site-1036667.mozfiles.com
- site-1036775.mozfiles.com
- site-1037130.mozfiles.com
- site-1036779.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report