SUSPICIOUS — tasenili.pdf
SUSPICIOUS — tasenili.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
547e51b6a3d28c25134c24f7f028fd8f4783274e1d4b10468c7a2d06c566f58d - SHA-1:
af8d5b00660b6bba94032396be50fb210ca5c641 - MD5:
a86d710a7cca171adaf8540ff5560f18 - ssdeep:
1536:aGFEpZl1FizobnYBbYTM2WXggROuGqVHDthPh7GToZRs:DFEp5nxTM2WXBRvH5htGTf - TLSH:
T1EF36BFF31097ED4EBA8B2F07BDB60069614AD34DB122D790154C763DD5ACABE3E10262 - Submitted as: tasenili.pdf
- File type: pdf · Size: 66467 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=nearpow%20timer%20manual%20t329c, https://cdn.shopify.com/s/files/1/0499/2480/0673/files/what_sound_does_rain_make_onomatopoeia.pdf, https://cdn.shopify.com/s/files/1/0431/2930/7293/files/lulibunej.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=nearpow%20timer%20manual%20t329c
- https://cdn.shopify.com/s/files/1/0499/2480/0673/files/what_sound_does_rain_make_onomatopoeia.pdf
- https://cdn.shopify.com/s/files/1/0431/2930/7293/files/lulibunej.pdf
- https://cdn.shopify.com/s/files/1/0484/6262/6970/files/moses_40_years_meme.pdf
- https://cdn.shopify.com/s/files/1/0496/2910/2244/files/kizewatukitobapajebita.pdf
- https://uploads.strikinglycdn.com/files/310b2a1c-64fd-4232-89cc-e4074c053ca8/52567493129.pdf
- https://uploads.strikinglycdn.com/files/94656f65-0b5f-4c31-a442-49c233d5edfc/bevodejexi.pdf
- https://uploads.strikinglycdn.com/files/4498aa55-6226-49d9-b63b-97e3c9540118/89152606213.pdf
- https://cdn.shopify.com/s/files/1/0488/1062/3141/files/talepopu.pdf
- https://cdn.shopify.com/s/files/1/0266/8121/3100/files/bit_heroes_mod_apk_happymod.pdf
- https://cdn.shopify.com/s/files/1/0501/6407/2613/files/incoterms_2020_italiano.pdf
- https://cdn.shopify.com/s/files/1/0502/7446/8037/files/english_guide_for_class_10.pdf
- https://cdn.shopify.com/s/files/1/0429/4852/6246/files/62766621829.pdf
- https://cdn-cms.f-static.net/uploads/4369914/normal_5f89085d9dc7f.pdf
- https://cdn-cms.f-static.net/uploads/4373755/normal_5f88f9f05517c.pdf
- https://cdn-cms.f-static.net/uploads/4367617/normal_5f8753011cba1.pdf
- https://uploads.strikinglycdn.com/files/083fbc80-3b7e-469e-9333-7b0dd0ced228/88862961264.pdf
- https://uploads.strikinglycdn.com/files/0b390901-ac1d-4f57-b75c-81decb308ba5/viwav.pdf
- https://uploads.strikinglycdn.com/files/dfc2a17e-ceb9-46d2-ad82-d1b56741b462/gevorigapasarekafepun.pdf
- https://uploads.strikinglycdn.com/files/93d628a7-862e-40ae-8c84-516e542a6b7b/pixatobaxedexu.pdf
- https://cdn.shopify.com/s/files/1/0481/3989/4947/files/44128840961.pdf
- https://cdn.shopify.com/s/files/1/0428/8777/4374/files/65508163409.pdf
- https://cdn.shopify.com/s/files/1/0499/4865/5784/files/jixinotagafi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report