SUSPICIOUS — 67007724866.pdf
SUSPICIOUS — 67007724866.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
390c5ed75835b87ac886faa370134fddff8d8d226c444cf8434ad4a7f36f3f18 - SHA-1:
d899067c89dd0e1fbe5684cc67594c123ccdad9f - MD5:
11848ba9645f899d0903c41bb4962ef9 - ssdeep:
1536:YGF3+0DaHstzgrVL5aHtsaLEXsFjiz/GBT/hzRRh7y:1Fu0DamKVL5aNsaLoscz/ydRi - TLSH:
T1BD35BFF3509BED8C7AC39B93AEA605646186C28D3227EA5055CD776C887C1BC7F10CA1 - Submitted as: 67007724866.pdf
- File type: pdf · Size: 59230 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:PDF/Phish.RA!MTB
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=wayanad+tourism+guide+wayanad+%25E0%25B4%2595%25E0%25B5%2587%25E0%25B4%25B0%25E0%25B4%25B3%25E0%25B4%2582, https://uploads.strikinglycdn.com/files/ca680977-a6f4-426e-884b-a472a2c729d5/xebuzezipatareter.pdf, https://uploads.strikinglycdn.com/files/59453c14-4ff3-4830-9b06-2569bc460fbc/61894561882.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=wayanad+tourism+guide+wayanad+%25E0%25B4%2595%25E0%25B5%2587%25E0%25B4%25B0%25E0%25B4%25B3%25E0%25B4%2582
- https://uploads.strikinglycdn.com/files/ca680977-a6f4-426e-884b-a472a2c729d5/xebuzezipatareter.pdf
- https://uploads.strikinglycdn.com/files/59453c14-4ff3-4830-9b06-2569bc460fbc/61894561882.pdf
- https://uploads.strikinglycdn.com/files/a3c5db70-5057-4c22-a043-e3a096483412/87817580817.pdf
- https://uploads.strikinglycdn.com/files/a4b7f02d-a766-4776-9ed5-27fed37ccb0d/89425113686.pdf
- https://uploads.strikinglycdn.com/files/826828b1-acb9-490c-b2e4-bc75108cc936/nizedaf.pdf
- https://uploads.strikinglycdn.com/files/3fda17bc-73c6-48ef-8b8b-0afe15825769/vomasalefekorujinepufatil.pdf
- http://dixizipi.ladderbird.com/uploads/1/3/2/6/132681352/1971852.pdf
- http://files.dorothyphillips.net/uploads/1/3/1/3/131383476/boluzoromezisob.pdf
- https://uploads.strikinglycdn.com/files/5672fb56-0018-4d1a-bd88-ee5a20df915d/77041050036.pdf
- https://uploads.strikinglycdn.com/files/64c08f54-df25-461f-a00c-ce13245ddf19/gunosoxelupeb.pdf
- https://uploads.strikinglycdn.com/files/c55492b3-0ba3-411f-8f27-2a7e0f5ba1a4/98393569708.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- dixizipi.ladderbird.com
- files.dorothyphillips.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report