SUSPICIOUS — 60567262106.pdf
SUSPICIOUS — 60567262106.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
1778ec44f07421ff9643d53dbed07ee1ac0c7f3fe58f24698d201746adcfd967 - SHA-1:
15c00a020741983518c00e3f08aadb3beeebf9d4 - MD5:
b76510b38c1e13f7cb3becdd094284d0 - ssdeep:
768:ngGzpDBe8AUZjGdJpudaLM80LjeCc5zfVsrfqsfTUuxeoX2n8w5y2swm:gGFFek8kjszfurfDfTUuAoi8wVswm - TLSH:
T17C329DF351A7EC8C7B8B9F17ADAB005AB14AD7C96122976014C87B2CC47C5ED6E10A21 - Submitted as: 60567262106.pdf
- File type: pdf · Size: 47240 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=basic+mathematics+test+with+answers+pdf, https://cdn-cms.f-static.net/uploads/4366331/normal_5f872d5f205aa.pdf, https://cdn-cms.f-static.net/uploads/4370764/normal_5f88bdcbddb96.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=basic+mathematics+test+with+answers+pdf
- https://cdn-cms.f-static.net/uploads/4366331/normal_5f872d5f205aa.pdf
- https://cdn-cms.f-static.net/uploads/4370764/normal_5f88bdcbddb96.pdf
- https://cdn-cms.f-static.net/uploads/4365552/normal_5f8702849917b.pdf
- https://cdn-cms.f-static.net/uploads/4368242/normal_5f887372974d9.pdf
- https://cdn-cms.f-static.net/uploads/4370073/normal_5f88bd9c78fd2.pdf
- https://cdn-cms.f-static.net/uploads/4365551/normal_5f874fe6314a5.pdf
- https://uploads.strikinglycdn.com/files/35ff1dfa-f8fa-4c22-8df3-49229023afc6/tepajenolugosuku.pdf
- https://uploads.strikinglycdn.com/files/c27d7a8b-0227-47ab-b05d-3cc693ef0a63/77976978388.pdf
- https://uploads.strikinglycdn.com/files/49b8ade9-9585-406c-9a80-44cbb10c4976/45479261474.pdf
- https://cdn.shopify.com/s/files/1/0428/6378/8188/files/78790935687.pdf
- https://cdn.shopify.com/s/files/1/0438/4908/9186/files/carta_de_esculapio_a_su_hijo_resumen.pdf
- https://cdn.shopify.com/s/files/1/0486/2879/3512/files/suunto_vytec_dive_computer_manual.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/9639254.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/7805117.pdf
- https://uploads.strikinglycdn.com/files/bdaf4499-67e3-426e-b8c1-97a8c4b672df/bemopeduwupemeze.pdf
- https://uploads.strikinglycdn.com/files/0bd9169e-4984-4b9a-8f67-85b17421716f/3858601683.pdf
- https://uploads.strikinglycdn.com/files/538d573c-85c1-4fab-9eaf-7f7cf4ae6c57/kiziniboxamoreg.pdf
- https://uploads.strikinglycdn.com/files/dd95b32f-69a9-45c0-a725-155ba3027001/83649998659.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- tavumake.weebly.com
- mogilifus.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report