SUSPICIOUS — 83656598966.pdf
SUSPICIOUS — 83656598966.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
34dd3ad74b5041a14eb0de8cc5f2faa7a2469f5eacbfbb91a7f2dfb0ceea0a35 - SHA-1:
3212be16964e70d6749a955409491f0a4ee7ebd7 - MD5:
74e392babec2da1cdd764fb3c6728f35 - ssdeep:
768:4gGzpD3603PZPfSGhkvGGExcFynK3TPOING6FZ8MHt96n/p2Y9o/x7B:VGFrz3ncGLcFyn0n46FOqb2R2j/x7B - TLSH:
T1F5318DF7109BED481E86AB579EF214A5A195C3487133B36448DC7BBC88B81FCAF10861 - Submitted as: 83656598966.pdf
- File type: pdf · Size: 40992 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=estadistica+para+negocios+y+economia+anderson+12+edicion+pdf, http://files.dcandevents.com/uploads/1/3/2/6/132682530/dokoduketob.pdf, http://kewet.cornellactuarialsociety.com/uploads/1/3/0/9/130969627/rojikavugikilej-xavukoponupi-litix-vipewoduzafomom.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=estadistica+para+negocios+y+economia+anderson+12+edicion+pdf
- http://files.dcandevents.com/uploads/1/3/2/6/132682530/dokoduketob.pdf
- http://kewet.cornellactuarialsociety.com/uploads/1/3/0/9/130969627/rojikavugikilej-xavukoponupi-litix-vipewoduzafomom.pdf
- http://files.familytreemandvbaker.com/uploads/1/3/1/4/131453432/dibaborekupuxu_gezit_vusafejovejojo_raboda.pdf
- http://jibivos.carpetcleaningstpete.com/uploads/1/3/0/7/130738948/zikuvunowimabafasor.pdf
- http://files.cmjwny.org/uploads/1/3/0/7/130775251/7391483.pdf
- http://files.pathofthepilots.com/uploads/1/3/2/6/132683463/3075195.pdf
- https://site-1037240.mozfiles.com/files/1037240/gawabagate.pdf
- https://site-1036820.mozfiles.com/files/1036820/tinalevixufarawopuj.pdf
- https://site-1036944.mozfiles.com/files/1036944/8892620268.pdf
- https://site-1038539.mozfiles.com/files/1038539/voruwifidigupupuj.pdf
- http://davaj.brunswickmainecoinclub.com/uploads/1/3/1/8/131856539/kivifimex-nimukofi-xeruz-dexinuriwowu.pdf
- http://files.wpca.org.za/uploads/1/3/1/8/131856353/f533c3e.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- files.dcandevents.com
- kewet.cornellactuarialsociety.com
- files.familytreemandvbaker.com
- jibivos.carpetcleaningstpete.com
- files.cmjwny.org
- files.pathofthepilots.com
- site-1037240.mozfiles.com
- site-1036820.mozfiles.com
- site-1036944.mozfiles.com
- site-1038539.mozfiles.com
- davaj.brunswickmainecoinclub.com
- files.wpca.org.za
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report