SUSPICIOUS — 75875621240.pdf
SUSPICIOUS — 75875621240.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
18277eea6ddf4d00a0ec3d6628fe9335d7bdcb449e6aec43ec3d8babb4b751a3 - SHA-1:
1cafaa313131ac08bca3ba89c4032bf073324bf6 - MD5:
7fda27871a016af425e1ac5ec1de3b24 - ssdeep:
768:mgGzpDtuW9xuCv3Sp5j31Fw7OGjUmwRYF+HK:zGFhuK6xOO4UmmYFmK - TLSH:
T128317DF35497DD8C7A87AB0399E71499619ADB4C2232D7A055C8776CC4BC2BDAF10820 - Submitted as: 75875621240.pdf
- File type: pdf · Size: 40783 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=univox+superfuzz+pcb, https://uploads.strikinglycdn.com/files/7acd733d-db0e-4d91-aada-a8daca32cd3e/rawiv.pdf, https://uploads.strikinglycdn.com/files/df4720e5-124e-4895-b89d-b8c0704d5066/56839319444.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=univox+superfuzz+pcb
- https://uploads.strikinglycdn.com/files/7acd733d-db0e-4d91-aada-a8daca32cd3e/rawiv.pdf
- https://uploads.strikinglycdn.com/files/df4720e5-124e-4895-b89d-b8c0704d5066/56839319444.pdf
- https://uploads.strikinglycdn.com/files/fe23cac3-7661-4325-8335-54133a3824ee/gonojibixadu.pdf
- http://files.mycookielab.com/uploads/1/3/0/7/130775365/2c31dd2.pdf
- http://bomaxim.zenithcounsellingandconversation.com/uploads/1/3/0/8/130813030/af28ed950b5.pdf
- http://bofos.womenofpurposeglobal.com/uploads/1/3/2/6/132681812/6ee09dc19.pdf
- http://files.northpolkfoundation.com/uploads/1/3/1/8/131856205/641697.pdf
- http://files.profileperformancedirect.com/uploads/1/3/0/8/130873708/jugexunogifalupedev.pdf
- http://binalom.vinoetamicis.com/uploads/1/3/1/4/131406821/1425fc6c8d4.pdf
- http://nawurune.worldtripgirl.com/uploads/1/3/1/0/131070487/wituxapux_dujogezoto.pdf
- https://site-1036973.mozfiles.com/files/1036973/19555915587.pdf
- https://site-1038455.mozfiles.com/files/1038455/67376861670.pdf
- https://site-1043124.mozfiles.com/files/1043124/subozetusapevogej.pdf
- https://site-1044306.mozfiles.com/files/1044306/76420537354.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- files.mycookielab.com
- bomaxim.zenithcounsellingandconversation.com
- bofos.womenofpurposeglobal.com
- files.northpolkfoundation.com
- files.profileperformancedirect.com
- binalom.vinoetamicis.com
- nawurune.worldtripgirl.com
- site-1036973.mozfiles.com
- site-1038455.mozfiles.com
- site-1043124.mozfiles.com
- site-1044306.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report