SUSPICIOUS — 93905705011.pdf
SUSPICIOUS — 93905705011.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
e6460d0f2d80b7e5ac29ea4491b2745bd596be2436afc11a19992dcf8d347794 - SHA-1:
266c220efbc104bcdc6e10e28101f0ad3f83659e - MD5:
60cd919f366ebc10c57a05a126014ddb - ssdeep:
768:kgGzpDWSmCXorlHfwJSsqtN9qagbXAV3rAB0/epaqS:RGFSQBY3tN9qaEwnepVS - TLSH:
T126309DF37097DD4C66C5AB072EAE11B964C5C64C70239A645E84FB2C90FE27E7E20960 - Submitted as: 93905705011.pdf
- File type: pdf · Size: 38968 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=suspicious+minds+guitar+tab+pdf, https://uploads.strikinglycdn.com/files/2b80b0f6-0e79-4cc4-9a79-ffa40e481a64/wasefoluxuxudimojorib.pdf, https://uploads.strikinglycdn.com/files/6d0804ca-0eed-4df3-a7c7-5fe2e40ed0f8/50287557819.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=suspicious+minds+guitar+tab+pdf
- https://uploads.strikinglycdn.com/files/2b80b0f6-0e79-4cc4-9a79-ffa40e481a64/wasefoluxuxudimojorib.pdf
- https://uploads.strikinglycdn.com/files/6d0804ca-0eed-4df3-a7c7-5fe2e40ed0f8/50287557819.pdf
- https://uploads.strikinglycdn.com/files/baace5db-19db-40c7-8f70-28818ce770d4/degadavera.pdf
- https://uploads.strikinglycdn.com/files/b12d578a-103b-457e-9845-0b99ffcb2e91/30371932828.pdf
- https://uploads.strikinglycdn.com/files/424d7551-59f5-492b-90f2-fbb10efa1d06/12377686825.pdf
- http://files.spectrumsignscalifornia.com/uploads/1/3/1/4/131453213/bejojamumaz.pdf
- http://pagez.hipsterleaks.com/uploads/1/3/1/8/131856097/japuwu.pdf
- http://ganulaler.poexts.com/uploads/1/3/1/4/131438759/suwenuzuzawubepopata.pdf
- http://files.pureomyoga.net/uploads/1/3/1/8/131856574/93925.pdf
- http://gofitofe.ldavis.people.ua.edu/uploads/1/3/1/8/131856456/buturedabu-wetakirex.pdf
- http://kalawezet.studiobymeika.com/uploads/1/3/1/4/131453133/sesufuxefogu_bemudazogaloju.pdf
- https://site-1037094.mozfiles.com/files/1037094/21376477093.pdf
- https://site-1036955.mozfiles.com/files/1036955/49356990527.pdf
- https://site-1037176.mozfiles.com/files/1037176/34107286456.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- files.spectrumsignscalifornia.com
- pagez.hipsterleaks.com
- ganulaler.poexts.com
- files.pureomyoga.net
- gofitofe.ldavis.people.ua.edu
- kalawezet.studiobymeika.com
- site-1037094.mozfiles.com
- site-1036955.mozfiles.com
- site-1037176.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report