SUSPICIOUS — 38041874167.pdf
SUSPICIOUS — 38041874167.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
1329503c830266c34f3a0488617fe3918d7ac6925af9f8897d399ff435539b08 - SHA-1:
95e42c10b137a7c80cba64c973b2725ac1629685 - MD5:
d2d3edf30f172e4cf3c6554426793672 - ssdeep:
768:AgGzpD4pEpOX7OUbhCjHLDI/o/EXXU6NgGbO8Xr0pBb:NGFspZhWIQ/n6NN9ApBb - TLSH:
T1FF306BF350DBEE8CBA879743AEAB25695446C3486132D7A0419C772CC8BC77C6E11D60 - Submitted as: 38041874167.pdf
- File type: pdf · Size: 38217 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=windows+xp+error+sound, http://mipiw.janeemwaters.com/uploads/1/3/1/6/131606617/8fcb19848b6e.pdf, http://files.hirethespires.com/uploads/1/3/2/7/132710732/f69ff1cc484a.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=windows+xp+error+sound
- http://mipiw.janeemwaters.com/uploads/1/3/1/6/131606617/8fcb19848b6e.pdf
- http://files.hirethespires.com/uploads/1/3/2/7/132710732/f69ff1cc484a.pdf
- http://fodanal.thisiskellymaryanski.com/uploads/1/3/2/6/132682883/jekemiraliji.pdf
- http://files.asbwellness.com/uploads/1/3/1/3/131384604/jarojij.pdf
- http://files.azorthosociety.org/uploads/1/3/1/4/131437107/mawepefugibok.pdf
- http://files.globalpentorch.net/uploads/1/3/1/3/131398440/potugisevapu_fevuzexada_dufafuri.pdf
- http://sedun.farmcorgis.com/uploads/1/3/1/4/131453527/22d5bc21.pdf
- http://files.blueheronsynergy.com/uploads/1/3/1/4/131406999/1e08d4f4.pdf
- http://files.1antler.com/uploads/1/3/0/7/130738875/f1878e78a.pdf
- http://files.shawnhaymakeupartist.com/uploads/1/3/1/0/131070792/6478793.pdf
- http://xefexibod.isnaa.com/uploads/1/3/0/8/130814788/rumoxemukasolutot.pdf
- http://files.danielaweil.com/uploads/1/3/2/7/132741397/8907525.pdf
- http://mawepiso.foccm.com/uploads/1/3/2/7/132712109/nofajekubigo.pdf
- http://files.oakleighminiatures.co.uk/uploads/1/3/1/4/131438058/886dd2121.pdf
- https://uploads.strikinglycdn.com/files/6c1d1667-3496-4518-ab68-bf5f5faf49ab/batogo.pdf
- https://uploads.strikinglycdn.com/files/3f21e619-d972-4318-942a-4b331c80abff/35492850545.pdf
- https://uploads.strikinglycdn.com/files/031e4554-bb5c-4011-ac5a-e15d3701437d/93716287886.pdf
- https://uploads.strikinglycdn.com/files/1c0f8558-5061-4cca-b6ca-be137c2c2547/83511048973.pdf
- https://uploads.strikinglycdn.com/files/71b5c698-27ab-4572-9503-8f44f934cb72/51346807146.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- mipiw.janeemwaters.com
- files.hirethespires.com
- fodanal.thisiskellymaryanski.com
- files.asbwellness.com
- files.azorthosociety.org
- files.globalpentorch.net
- sedun.farmcorgis.com
- files.blueheronsynergy.com
- files.1antler.com
- files.shawnhaymakeupartist.com
- xefexibod.isnaa.com
- files.danielaweil.com
- mawepiso.foccm.com
- files.oakleighminiatures.co.uk
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report