SUSPICIOUS — 56370144468.pdf
SUSPICIOUS — 56370144468.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
eb8518bb9b0ec626dfadb026e2328c73b1560d0258836e4105866259a97ca236 - SHA-1:
5db8b7e73fe69d521cf6ab002d1cc7a4567da859 - MD5:
5c9ab7dc7ea96d6de9a05c83782364e2 - ssdeep:
1536:NGFPp19/+4KqKAjEx/QCfje2HjlHk+S2j:QFPp1kfxI85E+b - TLSH:
T14535CFF31097DD4C668A6B539ED62059A166E38C6133AB6008CC7B6DD4B87FD2F20B11 - Submitted as: 56370144468.pdf
- File type: pdf · Size: 62036 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=scum+admin+befehle, https://uploads.strikinglycdn.com/files/2a60d178-d011-4935-9ab6-07480d4b6a86/65686261573.pdf, https://uploads.strikinglycdn.com/files/8b49c42f-21ec-42b5-b9a0-ebd1b69e715b/98864975565.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=scum+admin+befehle
- https://uploads.strikinglycdn.com/files/2a60d178-d011-4935-9ab6-07480d4b6a86/65686261573.pdf
- https://uploads.strikinglycdn.com/files/8b49c42f-21ec-42b5-b9a0-ebd1b69e715b/98864975565.pdf
- https://uploads.strikinglycdn.com/files/329f2dae-5f21-4314-b901-e2010238054c/jojepef.pdf
- https://uploads.strikinglycdn.com/files/e353ea1b-236f-42a9-ae67-167142720ef2/tofisevupu.pdf
- https://uploads.strikinglycdn.com/files/95b9f34d-82ff-4dfc-b9ed-2c7108081f33/jipikab.pdf
- https://cdn.shopify.com/s/files/1/0436/4628/8025/files/red_wolf_special_adaptations.pdf
- https://cdn.shopify.com/s/files/1/0434/7956/4448/files/on_call_away_lyrics.pdf
- https://cdn.shopify.com/s/files/1/0481/8881/7562/files/nc_state_university_club_jobs.pdf
- https://site-1039753.mozfiles.com/files/1039753/59651730178.pdf
- https://site-1036735.mozfiles.com/files/1036735/rokuzimefusuv.pdf
- https://site-1036719.mozfiles.com/files/1036719/93157184813.pdf
- https://uploads.strikinglycdn.com/files/edebecb1-ebeb-45a1-b1c2-04da907a5c82/6737884772.pdf
- https://uploads.strikinglycdn.com/files/f5924eca-575d-429c-be74-d6b065c7fd9e/zaxulufegixeregomudozet.pdf
- https://uploads.strikinglycdn.com/files/1d5025dd-180e-42b4-a349-0eadc70effba/sufexemifukuvegiwadak.pdf
- https://uploads.strikinglycdn.com/files/696f8f75-3bf7-472b-99df-c758ad7b16ee/davutagazobisesu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1039753.mozfiles.com
- site-1036735.mozfiles.com
- site-1036719.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report