SUSPICIOUS — 93417109868.pdf
SUSPICIOUS — 93417109868.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
2e1d993956c43aa5a73baa1d92442a62104cc140c5317107753ea616824a8e85 - SHA-1:
1c615b5c3919ab463ece1b71d72a9a6c5dcc7888 - MD5:
6ea8a0283556c21a496eb5dc990bb038 - ssdeep:
768:9gGzpDfOzmpwWQ/jSAha7s0gMSUcCLHEXMbXTzvTBS6e7buJlBJiQ+4qca3C0r:+GFj5sGcMkMj3AyY4da3C0r - TLSH:
T182329EF35097CD4C7B86AF13ABAB104925C9C78CA123E26018D97B7CD5B82BC6E10971 - Submitted as: 93417109868.pdf
- File type: pdf · Size: 43406 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=anon+bot+discord, https://cdn.shopify.com/s/files/1/0498/4517/4439/files/52253377825.pdf, https://cdn-cms.f-static.net/uploads/4365620/normal_5f97b830b0040.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=anon+bot+discord
- https://cdn.shopify.com/s/files/1/0498/4517/4439/files/52253377825.pdf
- https://cdn-cms.f-static.net/uploads/4365620/normal_5f97b830b0040.pdf
- https://uploads.strikinglycdn.com/files/803c8805-3222-418d-9f83-822e75392d0d/dragon_nest_level_guide_2020.pdf
- https://cdn.shopify.com/s/files/1/0496/6468/8292/files/conduction_band_and_valence_band.pdf
- https://cdn.shopify.com/s/files/1/0505/0096/0411/files/55760467991.pdf
- https://cdn-cms.f-static.net/uploads/4368950/normal_5f937d0256354.pdf
- https://cdn.shopify.com/s/files/1/0483/2296/9764/files/tululitofelivunafaze.pdf
- https://cdn.shopify.com/s/files/1/0432/6454/0840/files/kuribaxipakutudamuzu.pdf
- https://cdn.shopify.com/s/files/1/0497/8032/6561/files/shark_navigator_vacuum_owners_manual.pdf
- https://cdn-cms.f-static.net/uploads/4409840/normal_5f95a589b8e4c.pdf
- https://uploads.strikinglycdn.com/files/14259049-971a-4a3f-9418-2629ace7bbc8/12117747304.pdf
- https://cdn-cms.f-static.net/uploads/4367297/normal_5f94df7f7211f.pdf
- https://cdn.shopify.com/s/files/1/0484/3637/9816/files/64227826015.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report