SUSPICIOUS — 89248156179.pdf
SUSPICIOUS — 89248156179.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
f7680ccb6efd90cd30b0ca9c8a28bc42206b1dcf56e36566493a8afed5890fc7 - SHA-1:
6010516bb3b825613e82d88705ced51ca856c9bd - MD5:
4af3110dc6e2efd90369ecfb64f5589f - ssdeep:
768:0gGzpDmRKql8RBohF4VteKYiaeHCyN46ze8ijUm:BGFaVAVtXYGiyN46a8ijUm - TLSH:
T140319DF310A7EC8C7A839B43A9F2215DA156D34D51229BA0688C773CC4FC6BD6E60961 - Submitted as: 89248156179.pdf
- File type: pdf · Size: 41082 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=mary+oliver+mindful, https://xonujofepip.weebly.com/uploads/1/3/4/3/134385468/3300982.pdf, https://bopiwode.weebly.com/uploads/1/3/4/3/134367631/5240354.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=mary+oliver+mindful
- https://xonujofepip.weebly.com/uploads/1/3/4/3/134385468/3300982.pdf
- https://bopiwode.weebly.com/uploads/1/3/4/3/134367631/5240354.pdf
- https://s3.amazonaws.com/falevi/sherburne_county_property_tax_calculator.pdf
- https://razixolinatu.weebly.com/uploads/1/3/4/3/134384461/5131357.pdf
- https://cdn.shopify.com/s/files/1/0431/7016/8992/files/clara_doctor_who_dalek.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/rebodi.pdf
- https://gazesomudari.weebly.com/uploads/1/3/1/0/131070071/zezasajikuwew.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/3171713.pdf
- https://bilewazivabo.weebly.com/uploads/1/3/2/8/132816117/a7987f824.pdf
- https://gujibimusexuwub.weebly.com/uploads/1/3/4/0/134042380/51eba39a1.pdf
- https://cdn.shopify.com/s/files/1/0505/4804/8057/files/arithmetic_shift_vs_logical_shift_verilog.pdf
- https://cdn.shopify.com/s/files/1/0497/3389/4298/files/3835048650.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/63d400e.pdf
- https://cdn.shopify.com/s/files/1/0433/0700/8168/files/brownie_pets_badge_worksheet.pdf
- https://kuzaloxamuw.weebly.com/uploads/1/3/1/4/131406684/9970068.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- xonujofepip.weebly.com
- bopiwode.weebly.com
- s3.amazonaws.com
- razixolinatu.weebly.com
- cdn.shopify.com
- jatorogerujew.weebly.com
- gazesomudari.weebly.com
- boguvetasitob.weebly.com
- bilewazivabo.weebly.com
- gujibimusexuwub.weebly.com
- vozunutav.weebly.com
- kuzaloxamuw.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report