SUSPICIOUS — 67736823025.pdf
SUSPICIOUS — 67736823025.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e707ce70e706145121f36a13f23d069bd8fc13866326fb4005e36b4b94f161a1 - SHA-1:
5e8026599297003b87d21de56afcb434ded0cb99 - MD5:
ef2f2f7770a22f52a06d9126fc8a93b9 - ssdeep:
768:NegGzpDM5+u+x0k5ksXkTDX1vUhZL5mzIrmnlXHAYQzlCgbUB:JGFwB85X0TDFvUwzCmlXVQzlCgbUB - TLSH:
T108329EF350A7ED5C7A86AB079EBA1149904AD3883033A6B055CC776DC47CAFD6F40A60 - Submitted as: 67736823025.pdf
- File type: pdf · Size: 43768 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=the+red+pyramid+graphic+novel+online+free, https://uploads.strikinglycdn.com/files/c48604ec-4b95-49ee-a0ef-72acce6e1867/zejifakazirofiputemema.pdf, https://uploads.strikinglycdn.com/files/690bad78-3f39-4267-bac3-d23146dc50b7/57542669812.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=the+red+pyramid+graphic+novel+online+free
- https://uploads.strikinglycdn.com/files/c48604ec-4b95-49ee-a0ef-72acce6e1867/zejifakazirofiputemema.pdf
- https://uploads.strikinglycdn.com/files/690bad78-3f39-4267-bac3-d23146dc50b7/57542669812.pdf
- https://uploads.strikinglycdn.com/files/9573d274-3db7-421d-a42d-6e529b46e220/rurafika.pdf
- https://uploads.strikinglycdn.com/files/c4dcb33e-1020-416e-8408-0f888d089990/47617880105.pdf
- https://uploads.strikinglycdn.com/files/5bc528ee-db5e-4fb8-b6e8-c329af49e62b/64606599877.pdf
- https://site-1036815.mozfiles.com/files/1036815/mekopuzurixuku.pdf
- https://site-1039903.mozfiles.com/files/1039903/525815854.pdf
- https://site-1037022.mozfiles.com/files/1037022/fijasegibow.pdf
- https://uploads.strikinglycdn.com/files/3176c308-4f92-4bc5-a0c1-0676581667fa/55665791335.pdf
- https://uploads.strikinglycdn.com/files/670d31c6-d3ea-4d66-930f-72b7d32e14e9/mawuledopupunefenusezojul.pdf
- https://uploads.strikinglycdn.com/files/39a0def3-26c5-4086-8731-c0b2b64f5523/fesoretevejixubini.pdf
- https://uploads.strikinglycdn.com/files/576439e8-7ce0-45ee-969d-d4c751b805dd/lejozi.pdf
- https://uploads.strikinglycdn.com/files/45e33921-e57f-463c-9848-22ae24d2098c/popaw.pdf
- https://site-1037124.mozfiles.com/files/1037124/40961736671.pdf
- https://site-1044115.mozfiles.com/files/1044115/61716486603.pdf
- https://site-1036751.mozfiles.com/files/1036751/wukutidomoposazexakogat.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1036815.mozfiles.com
- site-1039903.mozfiles.com
- site-1037022.mozfiles.com
- site-1037124.mozfiles.com
- site-1044115.mozfiles.com
- site-1036751.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report