SUSPICIOUS — 95140387643.pdf
SUSPICIOUS — 95140387643.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
41530e7c5301281b56e3e8835c94ca18bdae4607b087a5ff58b3cdf12d69ef0e - SHA-1:
1960cbe0ca9a978277e82569e61048c1c970ab60 - MD5:
66269c86fe918dd5a6e381b9ac31bab5 - ssdeep:
768:xOgGzpDd1GpZsoTzWsnjt3aGGksH2lz8U8YdiWZ//O/bvnfSMHz7+kwo:VGFZ1zoTRJa3ksH+J8YdvZ/2/bvqw+kP - TLSH:
T1B5328DF39443EE8C7ACB9B036CF624556186C64861379BA414D9BB7CC8BC5FDAE04920 - Submitted as: 95140387643.pdf
- File type: pdf · Size: 44266 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=class+10+english+grammar+notes+pdf+free+download, http://luzagez.tiarasandfeatherdusters.com/uploads/1/3/0/9/130969648/jakotijetezujili.pdf, http://nawonew.a-1autoinc.com/uploads/1/3/1/4/131453724/sozavosijun-gizamugano-xaxusufuzevi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=class+10+english+grammar+notes+pdf+free+download
- http://luzagez.tiarasandfeatherdusters.com/uploads/1/3/0/9/130969648/jakotijetezujili.pdf
- http://nawonew.a-1autoinc.com/uploads/1/3/1/4/131453724/sozavosijun-gizamugano-xaxusufuzevi.pdf
- http://files.we-holidays.com/uploads/1/3/2/3/132302859/konizumutar.pdf
- http://files.lighane.com/uploads/1/3/1/3/131379373/wijop-xulitonatafezi-sezizuzawagoja.pdf
- http://fibimo.chestnutstreetflowers.com/uploads/1/3/0/8/130874498/5e398b5721a2c56.pdf
- https://site-1036852.mozfiles.com/files/1036852/nagofajivexewijo.pdf
- https://site-1036719.mozfiles.com/files/1036719/nelezapaxolir.pdf
- https://site-1037120.mozfiles.com/files/1037120/94786985170.pdf
- https://site-1036868.mozfiles.com/files/1036868/lokuwonaxuzowavumixez.pdf
- https://site-1036684.mozfiles.com/files/1036684/13832242828.pdf
- http://janadade.gronowskicenter.org/uploads/1/3/1/3/131381761/c29fcc7052d.pdf
- http://files.huntsvillepsych.com/uploads/1/3/1/4/131452934/4912309.pdf
- http://files.in-themoment.net/uploads/1/3/0/7/130775612/d19e0.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- luzagez.tiarasandfeatherdusters.com
- nawonew.a-1autoinc.com
- files.we-holidays.com
- files.lighane.com
- fibimo.chestnutstreetflowers.com
- site-1036852.mozfiles.com
- site-1036719.mozfiles.com
- site-1037120.mozfiles.com
- site-1036868.mozfiles.com
- site-1036684.mozfiles.com
- janadade.gronowskicenter.org
- files.huntsvillepsych.com
- files.in-themoment.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report