SUSPICIOUS — 17223299912.pdf
SUSPICIOUS — 17223299912.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
5c1c98430c6c871d34083228ab08febd386c9f745bd2938d4f134177317a962c - SHA-1:
cd0ab073c93d74f45d0b5790a76c20b28e6c7bc9 - MD5:
7c9210bae35356bd2113ec2caf9dfbe3 - ssdeep:
768:0gGzpD5XJTJ3Nva9hp6Ffx4LuLZAfngU2EQC23geISXRf9zdBzZrHLy3NdA3kN:BGFNXRLZAvgPPAS1lfzZzLcdA3kN - TLSH:
T1A832AEF31053DD8E7AC79B83A9F7019A6149D68D7132A62005C8BB2CC5BC6BC7F11961 - Submitted as: 17223299912.pdf
- File type: pdf · Size: 44116 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=livro+auditoria+fiscal+e+tribut%25C3%25A1ria+pdf, https://cdn.shopify.com/s/files/1/0428/4776/4647/files/arcade_emulator_android_apk.pdf, https://cdn.shopify.com/s/files/1/0432/2630/0577/files/57100806558.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=livro+auditoria+fiscal+e+tribut%25C3%25A1ria+pdf
- https://cdn.shopify.com/s/files/1/0434/3952/1958/files/67522105375.pdf
- https://cdn.shopify.com/s/files/1/0428/4776/4647/files/arcade_emulator_android_apk.pdf
- https://cdn.shopify.com/s/files/1/0432/2630/0577/files/57100806558.pdf
- https://cdn.shopify.com/s/files/1/0430/2857/8467/files/car_engine_oil_capacity.pdf
- https://cdn.shopify.com/s/files/1/0434/1910/7480/files/achievement_motivation_meaning.pdf
- https://site-1037253.mozfiles.com/files/1037253/72041139789.pdf
- http://files.cassiemseinuk.com/uploads/1/3/0/8/130874431/3225767.pdf
- http://wuberorus.littlebudtea.com/uploads/1/3/1/6/131637043/tiweneseva-karanegig-xejuxor-mujumivalimo.pdf
- http://files.bjemdesigns.com/uploads/1/3/1/1/131163667/baxizis_zupoxefe.pdf
- https://cdn.shopify.com/s/files/1/0435/9657/8979/files/92999494625.pdf
- https://cdn.shopify.com/s/files/1/0431/7564/1247/files/54179042520.pdf
- https://cdn.shopify.com/s/files/1/0431/3645/0717/files/registration_form_html_template_themeforest.pdf
- https://cdn.shopify.com/s/files/1/0437/5861/6733/files/88416072173.pdf
- https://cdn.shopify.com/s/files/1/0461/4488/0803/files/vaziro.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- site-1037253.mozfiles.com
- files.cassiemseinuk.com
- wuberorus.littlebudtea.com
- files.bjemdesigns.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report