MALICIOUS — 64591975184.pdf
MALICIOUS — 64591975184.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
ee38cc0b86b20ba4d3767864bef41ca4cba83f00ca98e9b978b528283496bb71 - SHA-1:
62c2a1ffd0925a952fd464ed8baeb2684ea68c44 - MD5:
ff261a61d1c661bc13c11aa0066f027a - ssdeep:
768:PgGzpDtyOXvDEEJQfaG/4z3iqhm7punnC6LIPdf/OBtDUk3rjinrP:4GF5/9C9/QUepLUdeBBUk3rjinrP - TLSH:
T1ED32BEF340ABDC8CB9C9AB0399F72055514AD78D7233D26045897B2ED5BC2BCAF10961 - Submitted as: 64591975184.pdf
- File type: pdf · Size: 44159 bytes
- Verdict: malicious (88/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://cctraff.ru/strik?keyword=gender+is+a+social+construct+pdf, https://uploads.strikinglycdn.com/files/05a4cca5-5685-496a-9e0e-4cd642caf2bd/66126267206.pdf, https://uploads.strikinglycdn.com/files/5038f1a3-94bb-44c2-b978-ee88c090b3d0/77677502227.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=gender+is+a+social+construct+pdf
- https://uploads.strikinglycdn.com/files/05a4cca5-5685-496a-9e0e-4cd642caf2bd/66126267206.pdf
- https://uploads.strikinglycdn.com/files/5038f1a3-94bb-44c2-b978-ee88c090b3d0/77677502227.pdf
- https://uploads.strikinglycdn.com/files/c1075435-5464-49da-9a3d-4b15890a2cde/salakaluzu.pdf
- https://uploads.strikinglycdn.com/files/1a4d66d8-52e9-444a-8096-bd5baf46ae6d/76024428927.pdf
- https://uploads.strikinglycdn.com/files/f570c9cc-ebc9-426a-af2e-6587f739cdef/88357586045.pdf
- https://site-1036640.mozfiles.com/files/1036640/goturejumolorudiju.pdf
- https://site-1036900.mozfiles.com/files/1036900/46850176734.pdf
- https://site-1036941.mozfiles.com/files/1036941/71871733204.pdf
- https://site-1036969.mozfiles.com/files/1036969/lokamogarukukuf.pdf
- https://site-1037193.mozfiles.com/files/1037193/defulajabezelozomumosoje.pdf
- https://uploads.strikinglycdn.com/files/a4e7b78c-151c-4cd8-9f7e-31228fe570be/20896897690.pdf
- https://uploads.strikinglycdn.com/files/01a32d91-8633-4972-b771-89f992716611/sowigadawusumoxedewepuxal.pdf
- https://uploads.strikinglycdn.com/files/4e1f6534-18b7-4228-806e-e46988478487/vepasowotamaxonanuxowa.pdf
- http://files.helpaschoolfoundation.com/uploads/1/3/2/7/132741556/jakenedikapom-zoxepuxivulul-seludifigenufa.pdf
- http://nuxubukid.jenscontagiouscooking.com/uploads/1/3/1/4/131406071/sumokove_bedat_neken.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1036640.mozfiles.com
- site-1036900.mozfiles.com
- site-1036941.mozfiles.com
- site-1036969.mozfiles.com
- site-1037193.mozfiles.com
- files.helpaschoolfoundation.com
- nuxubukid.jenscontagiouscooking.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report