SUSPICIOUS — 52548846832.pdf
SUSPICIOUS — 52548846832.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
5c01cb067510fd66b998a17f8009d1a5aae6155c28647eeaf4feeb875450049c - SHA-1:
9b8ef2cbd19dc867c7df605805822509ca138a26 - MD5:
800105dd62f9501958c1bd282bc33f31 - ssdeep:
768:wgGzpDMpmAW+YAvkyULqAxctMDGTYcLD3I7xX5jRBBzw6eCK6r:dGFQpmlulMyTY0YtXLBRwjCK6r - TLSH:
T114309FF35197DC8C7B8A9F077DAB115EA14AD2897132D6A4589C332CC4BC6ED3E00A51 - Submitted as: 52548846832.pdf
- File type: pdf · Size: 37011 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=the+berenstain+bears+pdf+free+downlo, http://files.la-arts.org/uploads/1/3/1/4/131483254/kedena_tadobalor_vakowowide.pdf, http://nutev.trulypottedsucculents.com/uploads/1/3/0/8/130874524/jural-pomogirojaso-nujaromijo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=the+berenstain+bears+pdf+free+downlo
- http://files.la-arts.org/uploads/1/3/1/4/131483254/kedena_tadobalor_vakowowide.pdf
- http://nutev.trulypottedsucculents.com/uploads/1/3/0/8/130874524/jural-pomogirojaso-nujaromijo.pdf
- http://gefida.yourtattoostory.com/uploads/1/3/1/3/131378970/a141b.pdf
- http://files.jdlhomesvancouver.com/uploads/1/3/1/3/131379340/b0af1f.pdf
- http://files.annepauley.com/uploads/1/3/1/4/131453536/34cdfebc96970.pdf
- https://cdn.shopify.com/s/files/1/0484/6898/3958/files/zurexinezolonanunazal.pdf
- https://cdn.shopify.com/s/files/1/0438/5977/1557/files/cells_the_units_of_life_answers.pdf
- https://cdn.shopify.com/s/files/1/0483/1290/9979/files/resokodipejekanirizufibe.pdf
- https://cdn.shopify.com/s/files/1/0434/6649/0006/files/plot_multinomial_logistic_regression_in_r.pdf
- https://cdn.shopify.com/s/files/1/0430/3382/1347/files/welisusavibelazejorefipo.pdf
- http://files.walsh4one.com/uploads/1/3/2/6/132681767/24981cb55783.pdf
- http://files.westmilfordfarm.com/uploads/1/3/0/8/130873869/7980379.pdf
- http://kizavaza.solarplexusbeauty.com/uploads/1/3/0/7/130738950/7960947.pdf
- https://cdn.shopify.com/s/files/1/0492/0282/3331/files/vizukewozeborofunoreb.pdf
- https://cdn.shopify.com/s/files/1/0434/4525/6352/files/45843452573.pdf
- https://cdn.shopify.com/s/files/1/0433/0084/7780/files/rada_knife_sharpener_angle.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- files.la-arts.org
- nutev.trulypottedsucculents.com
- gefida.yourtattoostory.com
- files.jdlhomesvancouver.com
- files.annepauley.com
- cdn.shopify.com
- files.walsh4one.com
- files.westmilfordfarm.com
- kizavaza.solarplexusbeauty.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report