MALICIOUS — medela_manual_pump_lost_suction.pdf
MALICIOUS — medela_manual_pump_lost_suction.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (70/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
4666d33b2e1a710e855429e56f72e53cff0161181047cde1a02c46817e69402e - SHA-1:
be12ba2ed7222338b04365f8dcd937accf7c35b7 - MD5:
aa1bb4174bd94f61d40084240c7a380b - ssdeep:
768:SgGzpDYpBsOgMfFKWZB4NeMLjXlG67JF1CmSE0q0u7ePgNEp:PGFkpBuMfFpB4Ntjr736E0q0mugNEp - TLSH:
T150329EF744E7DD8CBA875B43A9A72499504AC38CA237E360498C7B6DC0BC67DAD10861 - Submitted as: medela_manual_pump_lost_suction.pdf
- File type: pdf · Size: 45385 bytes
- Verdict: malicious (70/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 70/100 is the fusion of 4 weighted signals:
- Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://gettraff.ru/strik?keyword=medela+manual+pump+lost+suction, https://uploads.strikinglycdn.com/files/a041bc3a-372b-47fc-b4cf-f20ad09f6633/86064610947.pdf, https://uploads.strikinglycdn.com/files/d4854d78-8cbc-444c-a0f5-1eaf6c74066a/kanna_master_blaster.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=medela+manual+pump+lost+suction
- https://uploads.strikinglycdn.com/files/a041bc3a-372b-47fc-b4cf-f20ad09f6633/86064610947.pdf
- https://uploads.strikinglycdn.com/files/d4854d78-8cbc-444c-a0f5-1eaf6c74066a/kanna_master_blaster.pdf
- https://uploads.strikinglycdn.com/files/319784f1-3042-4468-845f-e4f6324cc99f/laresufuve.pdf
- https://uploads.strikinglycdn.com/files/0ee8c869-c572-4658-baf8-a4b51a44dfa1/wagoku.pdf
- https://uploads.strikinglycdn.com/files/c513dd04-fbef-4d02-9b0d-29d422a119f6/18492920392.pdf
- https://uploads.strikinglycdn.com/files/1ee354d7-6657-497b-8bfe-ab2aff5adbdd/lejutediwidipububirofegol.pdf
- https://uploads.strikinglycdn.com/files/6e3233d3-6664-42e7-a7f3-16f6dd992806/tovakurite.pdf
- https://uploads.strikinglycdn.com/files/d23f1930-ff97-4917-b4e8-e5cd6bd554eb/32419082740.pdf
- https://uploads.strikinglycdn.com/files/74effa37-8a54-4c7d-a0ac-acc8a5ba1f0f/fabukenanufubuxovawavasof.pdf
- https://uploads.strikinglycdn.com/files/345e8fcd-5293-4f50-b97e-416bbf356218/78280429216.pdf
- https://uploads.strikinglycdn.com/files/a34377b1-c9ea-4a22-9f67-b8f9658753a7/35185522645.pdf
- https://uploads.strikinglycdn.com/files/8b3dde5c-72af-402d-a131-866aaf25fa2d/wazoniwal.pdf
- https://uploads.strikinglycdn.com/files/4b97636d-4634-4d05-b7f7-bb6bdd09f54c/dizawemaludijanesapod.pdf
- https://uploads.strikinglycdn.com/files/5a6e5124-7d02-4a56-9944-5bfe93933e13/19486910782.pdf
- https://uploads.strikinglycdn.com/files/c3e8160f-3062-4aeb-911c-bfdf0645d67c/74529588273.pdf
- https://tekegalesi.weebly.com/uploads/1/3/0/7/130740489/zunuwapu.pdf
- https://tumovapexawezan.weebly.com/uploads/1/3/1/3/131398362/jixupisepifej_wunitimu_gipopegifolo_zakedebimoga.pdf
- https://babinekisifuve.weebly.com/uploads/1/3/2/6/132696104/625781.pdf
- https://bubudatitiga.weebly.com/uploads/1/3/4/3/134308982/fubesanipogimi.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/kizerapu.pdf
- https://relogeseji.weebly.com/uploads/1/3/0/7/130739887/603817.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- tekegalesi.weebly.com
- tumovapexawezan.weebly.com
- babinekisifuve.weebly.com
- bubudatitiga.weebly.com
- fijojonibiw.weebly.com
- relogeseji.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report