SUSPICIOUS — leliriwadasolem.pdf
SUSPICIOUS — leliriwadasolem.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
2e01a701094a70899ed6156146d59422a5037be5f4a2ca5c94a3beaa20f3248b - SHA-1:
1016f32e84631e6022e7c9616fa3a9ae28e0301e - MD5:
1ecf6fdc634cd5ed78ed14095683027a - ssdeep:
768:AgGzpDWgAj2im8NFjclJyY2AshGL1goWZ+UhqFiyISby2rf:NGFCga5fhqgoWoUwMyISvf - TLSH:
T1C0308DF36057ED8C3ACBAB03AFE6119D60C6C78D5126966058D837ACC4BC6FD6E10921 - Submitted as: leliriwadasolem.pdf
- File type: pdf · Size: 36026 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=uos+degree+fee+challan+form, https://cdn.shopify.com/s/files/1/0484/9126/6198/files/cinco_de_mayo_comprehension_worksheet.pdf, https://cdn.shopify.com/s/files/1/0482/5700/7770/files/296034495.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=uos+degree+fee+challan+form
- https://cdn.shopify.com/s/files/1/0484/9126/6198/files/cinco_de_mayo_comprehension_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0482/5700/7770/files/296034495.pdf
- https://cdn.shopify.com/s/files/1/0439/3140/2395/files/awesome_games_done_quick_2020_schedule.pdf
- https://cdn.shopify.com/s/files/1/0434/6760/4128/files/krunker.io_unblocked_77.pdf
- https://cdn.shopify.com/s/files/1/0433/7798/3651/files/sda_bible_commentary.pdf
- https://cdn.shopify.com/s/files/1/0434/0586/9208/files/career_research_project_for_high_school_students.pdf
- https://cdn.shopify.com/s/files/1/0494/7086/5575/files/87203220405.pdf
- http://files.darwinsyantipolo.com/uploads/1/3/0/7/130775820/felineko_genugot_numumosuruvu.pdf
- http://files.qpsarx.com/uploads/1/3/0/8/130874115/fofawebajuzagutudub.pdf
- http://files.riagureja.com/uploads/1/3/1/6/131637352/xigukixe_jizotavex_fenitekebu.pdf
- http://files.iamdarrin.com/uploads/1/3/0/7/130776180/3302781.pdf
- http://wurelaj.5men104years.com/uploads/1/3/1/4/131438641/f6a77f461e6c633.pdf
- http://mebetajim.bluethunderbirdwoman.com/uploads/1/3/0/7/130739892/ruwetezare.pdf
- http://kotija.acct301.ehabacademy.com/uploads/1/3/0/8/130813714/bupolo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- files.darwinsyantipolo.com
- files.qpsarx.com
- files.riagureja.com
- files.iamdarrin.com
- wurelaj.5men104years.com
- mebetajim.bluethunderbirdwoman.com
- kotija.acct301.ehabacademy.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report