SUSPICIOUS — 66286354271.pdf
SUSPICIOUS — 66286354271.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
49dc6f45cfc1e9236e18eb7a5711b3bda25335f52c9b517d1b3277970833b4a0 - SHA-1:
f7be8b0ec222d3c66dad2f32d4097b8615543ec1 - MD5:
8334f0ce03f4b9513cb59899699b1957 - ssdeep:
1536:jGFMUkAr2buiidq3IscFPGHyTaXLRVUN0UMCjob7tb+MDb0Kmx:yFMURLscFPOV0Vj87Nlcx - TLSH:
T10137E0F311A7ED1C6687DF532EE6184E250ADE49227257B44489BBADC07CABDBD00E10 - Submitted as: 66286354271.pdf
- File type: pdf · Size: 74728 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=inductive+reasoning+definition+pdf, https://uploads.strikinglycdn.com/files/9c5806ad-da35-4290-9ff4-8cb4d598c26d/zofumopokafomunelonal.pdf, https://uploads.strikinglycdn.com/files/7761edb4-f5ed-49e9-9d15-53f74df3b8b3/15993846541.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=inductive+reasoning+definition+pdf
- https://uploads.strikinglycdn.com/files/9c5806ad-da35-4290-9ff4-8cb4d598c26d/zofumopokafomunelonal.pdf
- https://uploads.strikinglycdn.com/files/7761edb4-f5ed-49e9-9d15-53f74df3b8b3/15993846541.pdf
- https://uploads.strikinglycdn.com/files/aeb957f5-f071-403b-a7dd-b89ce32ee32e/14645310381.pdf
- https://cdn.shopify.com/s/files/1/0432/3259/2040/files/fast_reader_android.pdf
- https://cdn.shopify.com/s/files/1/0436/5520/0918/files/ralisation_d_un_amplificateur_audio.pdf
- https://uploads.strikinglycdn.com/files/7e25a8f3-932f-426f-ab0e-9f2bbdd8a7a7/fimilof.pdf
- https://uploads.strikinglycdn.com/files/3692abb4-9658-46b1-8878-acff280c2b0d/juzutonejigipox.pdf
- https://uploads.strikinglycdn.com/files/81f139cc-695c-48f8-ae38-996906645f66/dukifigavu.pdf
- http://saretazov.leiladyamy.com/uploads/1/3/2/6/132695643/2176a212a0.pdf
- http://files.kurtweissgerber.com/uploads/1/3/1/0/131071252/mimaguser.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- saretazov.leiladyamy.com
- files.kurtweissgerber.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report