SUSPICIOUS — 60537868267.pdf
SUSPICIOUS — 60537868267.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
33cc6e72c05f2835d360133f109fc05640bba3c2c5285b4865d3026ba906c8f3 - SHA-1:
859ae8aad39fd1399f222e36f76c906957bf422e - MD5:
61292d63f3df96bb909f7e62a11fad25 - ssdeep:
1536:ZGF+pojAQlIaC4jrxntgv9lfjeTQPaH+XsqmQZR:sF+pocaVKDoes6/mM - TLSH:
T1E034CEF35193EDCC76CB6717BEA3165E9249C7496033A76048C83B6DC4782BC6E10AA1 - Submitted as: 60537868267.pdf
- File type: pdf · Size: 53337 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=ishmael+daniel+quinn+pdf, https://site-1040326.mozfiles.com/files/1040326/83110663604.pdf, https://site-1036786.mozfiles.com/files/1036786/vazomukisuniji.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=ishmael+daniel+quinn+pdf
- https://site-1040326.mozfiles.com/files/1040326/83110663604.pdf
- https://site-1036786.mozfiles.com/files/1036786/vazomukisuniji.pdf
- https://site-1038375.mozfiles.com/files/1038375/62496499614.pdf
- https://site-1039174.mozfiles.com/files/1039174/nuxuzi.pdf
- http://files.harborimpactministries.com/uploads/1/3/1/8/131856851/3616556.pdf
- http://files.jakewheeler.com/uploads/1/3/1/0/131070098/pazidetifi.pdf
- http://vusokenun.flyinghorsearts.com/uploads/1/3/1/6/131637881/5a500f.pdf
- http://files.aikidoithaca.com/uploads/1/3/0/7/130739495/c7586734e09.pdf
- http://migajaput.forrestfitness.com/uploads/1/3/1/4/131406717/8584702.pdf
- https://uploads.strikinglycdn.com/files/cb0b64b1-3664-4e53-910a-6ca8df4c97bc/wadubijarijibuxad.pdf
- https://uploads.strikinglycdn.com/files/a02d949c-2980-4cc7-9c7f-469d29613c1c/9576226853.pdf
- https://uploads.strikinglycdn.com/files/bfba6511-c3cb-4a50-b57b-a4a7679aca16/pizepabevujarubeje.pdf
- https://uploads.strikinglycdn.com/files/5e1f706c-efa5-41f5-a9b1-1d28962d884f/14967565739.pdf
- https://uploads.strikinglycdn.com/files/990265ef-36ba-4f4f-8058-c92cab5c9c1c/50663166754.pdf
- https://site-1043098.mozfiles.com/files/1043098/7764995221.pdf
- https://site-1039834.mozfiles.com/files/1039834/23404578454.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1040326.mozfiles.com
- site-1036786.mozfiles.com
- site-1038375.mozfiles.com
- site-1039174.mozfiles.com
- files.harborimpactministries.com
- files.jakewheeler.com
- vusokenun.flyinghorsearts.com
- files.aikidoithaca.com
- migajaput.forrestfitness.com
- uploads.strikinglycdn.com
- site-1043098.mozfiles.com
- site-1039834.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report