SUSPICIOUS — toberewo.pdf
SUSPICIOUS — toberewo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
57f81e6652dada209e58e25794177653de36be4e70ea1765f1ad8e7e158dae7c - SHA-1:
3705ce8102d967e0161ced8b2142b09919f2f9f7 - MD5:
ffca8ae168313de990ff47bb0eacd260 - ssdeep:
1536:MGFwpNlVRi/ppxe3LI3WoWAvu2GnQoOokDN/:pFwpBQ/pG7f92GnQoOoO - TLSH:
T18235C0F35153EC8D368F7F43A9D6104A51865B896022D7A058C8772CD4FCBFCAE54A22 - Submitted as: toberewo.pdf
- File type: pdf · Size: 59259 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=sap+note+1804812, https://cdn.shopify.com/s/files/1/0488/1553/8341/files/33326598117.pdf, https://cdn.shopify.com/s/files/1/0484/3113/6936/files/kai_hiwatari_x_reader.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=sap+note+1804812
- https://cdn.shopify.com/s/files/1/0488/1553/8341/files/33326598117.pdf
- https://cdn.shopify.com/s/files/1/0484/3113/6936/files/kai_hiwatari_x_reader.pdf
- https://cdn.shopify.com/s/files/1/0498/3809/6546/files/gottman_four_horsemen_quiz.pdf
- https://cdn.shopify.com/s/files/1/0483/4095/9383/files/92756135814.pdf
- https://cdn.shopify.com/s/files/1/0432/8531/5744/files/2625731428.pdf
- https://cdn.shopify.com/s/files/1/0499/5176/8731/files/katilovasudenokiziniridin.pdf
- https://cdn.shopify.com/s/files/1/0484/8327/0818/files/40751088435.pdf
- https://cdn.shopify.com/s/files/1/0430/4827/2023/files/wofiradoliwoja.pdf
- http://kapaxe.auseras.com/uploads/1/3/2/7/132710714/c4acf143c.pdf
- http://files.busywandering.com/uploads/1/3/1/6/131606133/wolezevo.pdf
- https://cdn.shopify.com/s/files/1/0496/5842/9593/files/nukitatilunabebalugat.pdf
- https://cdn.shopify.com/s/files/1/0480/8422/2116/files/woxogusisoj.pdf
- https://cdn.shopify.com/s/files/1/0431/5208/1053/files/death_cab_for_cutie_plans_songs.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- kapaxe.auseras.com
- files.busywandering.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report