SUSPICIOUS — 38892997912.pdf
SUSPICIOUS — 38892997912.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
fa39257f599f9c236f54e29115d7261ff27ab33942009da57e20d3b045e8539d - SHA-1:
777b4f32c7930a059a1ab1d39986a5ee7b716ca0 - MD5:
bba7aba6810a43e3ccb7fd8e5e431790 - ssdeep:
768:XgGzpDX72VZrYyv5034sIWdSWGiJq8PzIzqOrGJM0RV6:wGFraHo7HFq8PzIqYGJZRV6 - TLSH:
T1A4318EF314E7DD4C7A87AB07A9EB145D5189D28C5272AB6054D8377DC07C3BCAE40A22 - Submitted as: 38892997912.pdf
- File type: pdf · Size: 42844 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=madden+mobile+cydia+hack, https://uploads.strikinglycdn.com/files/428a6c6a-7cf9-4620-8d58-bf37b549e4b8/58074071080.pdf, https://uploads.strikinglycdn.com/files/ba39634f-ec41-4d57-b7e1-2bb3bdceace0/63243809542.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=madden+mobile+cydia+hack
- https://uploads.strikinglycdn.com/files/428a6c6a-7cf9-4620-8d58-bf37b549e4b8/58074071080.pdf
- https://uploads.strikinglycdn.com/files/ba39634f-ec41-4d57-b7e1-2bb3bdceace0/63243809542.pdf
- https://uploads.strikinglycdn.com/files/4eb7e662-9f27-42cb-b518-78f1cbc42f91/66590453048.pdf
- https://uploads.strikinglycdn.com/files/111d60ed-8ea9-4830-ac1a-b16fabe1b4fc/mifakizivibavokuxute.pdf
- https://uploads.strikinglycdn.com/files/4bd0db61-1c37-41e1-98eb-fcc3b8bcb91c/zudatafaxigola.pdf
- https://site-1039350.mozfiles.com/files/1039350/vilaviwasomugonate.pdf
- https://site-1042107.mozfiles.com/files/1042107/remew.pdf
- https://site-1036911.mozfiles.com/files/1036911/lomaxobepemope.pdf
- https://site-1036652.mozfiles.com/files/1036652/gamizizivulanaw.pdf
- https://site-1037282.mozfiles.com/files/1037282/retitufawifomejij.pdf
- https://site-1037240.mozfiles.com/files/1037240/gawabagate.pdf
- https://site-1036667.mozfiles.com/files/1036667/98923905302.pdf
- https://site-1036753.mozfiles.com/files/1036753/kaxiwagamurukejonujuju.pdf
- https://uploads.strikinglycdn.com/files/48afb3af-34e1-4303-8e17-4a5f2d868bfe/gazirewuj.pdf
- https://uploads.strikinglycdn.com/files/11cf12d8-faca-40e3-9b9c-455669d90c43/94439960404.pdf
- https://uploads.strikinglycdn.com/files/e1524fd3-6059-4b43-b54c-ef9a4d47d9e7/93147632523.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1039350.mozfiles.com
- site-1042107.mozfiles.com
- site-1036911.mozfiles.com
- site-1036652.mozfiles.com
- site-1037282.mozfiles.com
- site-1037240.mozfiles.com
- site-1036667.mozfiles.com
- site-1036753.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report