SUSPICIOUS — 63608615315.pdf
SUSPICIOUS — 63608615315.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
17b52d3023776ee69880d23e2e60032be91397939011b3194baa9f723d70a049 - SHA-1:
f5bf26c3cd738cc1f34aeccf71073f978f21b0c7 - MD5:
c1696f40a5b1281be76c038ecee9efca - ssdeep:
768:qgGzpD191aUUI99GeT2Zwv3vcS+JoiRph7ZIAKuhD2E4QjXlPWEnIjsUF:3GFJzp9GZwv3vcryUh9MS34QrlPzI4UF - TLSH:
T1E633BFF351E7ED886A865B4328F601682126D39C7232D7A449CC775CD4FC6FCAD10A60 - Submitted as: 63608615315.pdf
- File type: pdf · Size: 48710 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=lesser+demons+rs3+slayer, http://vuwasar.wendycooneylightingdesign.com/uploads/1/3/1/4/131438110/2893348.pdf, http://gitasamo.anglesborons.com/uploads/1/3/1/4/131454120/8067137.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=lesser+demons+rs3+slayer
- http://vuwasar.wendycooneylightingdesign.com/uploads/1/3/1/4/131438110/2893348.pdf
- http://gitasamo.anglesborons.com/uploads/1/3/1/4/131454120/8067137.pdf
- http://majom.northernvoices.com.au/uploads/1/3/2/7/132740412/petele.pdf
- https://site-1038590.mozfiles.com/files/1038590/wowifebubezebarete.pdf
- https://uploads.strikinglycdn.com/files/e031d859-78e9-47ea-ac93-59b98ba5315c/97028824852.pdf
- https://uploads.strikinglycdn.com/files/6df176f7-e8f5-44e1-97df-aff4e2b80faf/gutuwakazusepazikonide.pdf
- https://uploads.strikinglycdn.com/files/306fa7b1-87df-43af-8ef6-7c48b3ad8402/tokomaledoxetu.pdf
- https://uploads.strikinglycdn.com/files/5adf4a37-ebee-4354-86ed-efcd15a8afa2/80559983702.pdf
- https://uploads.strikinglycdn.com/files/facd4c2a-6cf7-4272-96b0-778c91cb3316/jafidasenevebesureg.pdf
- https://site-1038409.mozfiles.com/files/1038409/25149568437.pdf
- https://site-1042988.mozfiles.com/files/1042988/vexemifutokomoxamo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- vuwasar.wendycooneylightingdesign.com
- gitasamo.anglesborons.com
- majom.northernvoices.com.au
- site-1038590.mozfiles.com
- uploads.strikinglycdn.com
- site-1038409.mozfiles.com
- site-1042988.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report