SUSPICIOUS — 70184088725.pdf
SUSPICIOUS — 70184088725.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
5e2840f1468000b8e727ff7fe7a963ec9bb54ac635546cc20fe61c7fbb653887 - SHA-1:
08dc3888f0b56e75c0005744bbad1df385b49dec - MD5:
1bad6fbb08dbe3d227c5496ce471aa72 - ssdeep:
1536:9GFXKeGAWQj40KTgpK+W/id81rVgpcziI:AFXKeGNYpK+W/i2Ve0 - TLSH:
T1CE338EF340A7EC4D3AC79B03ADAA206DA15DDB496133E660148C772CC47C6BE7E50A61 - Submitted as: 70184088725.pdf
- File type: pdf · Size: 51516 bytes
- Verdict: suspicious (44/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=chrome+32+bit+windows+7, https://cdn-cms.f-static.net/uploads/4366035/normal_5f8731fb09167.pdf, https://cdn-cms.f-static.net/uploads/4368751/normal_5f8935e550963.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=chrome+32+bit+windows+7
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f8731fb09167.pdf
- https://cdn-cms.f-static.net/uploads/4368751/normal_5f8935e550963.pdf
- https://cdn-cms.f-static.net/uploads/4367005/normal_5f8768e3447cc.pdf
- https://cdn-cms.f-static.net/uploads/4366313/normal_5f87387137fd8.pdf
- https://cdn-cms.f-static.net/uploads/4374688/normal_5f89f1f3b2891.pdf
- https://cdn.shopify.com/s/files/1/0440/0149/3142/files/language_experience_approach_lea.pdf
- https://cdn.shopify.com/s/files/1/0431/8609/4242/files/interrogative_words_in_spanish_meaning.pdf
- https://cdn.shopify.com/s/files/1/0492/5027/1388/files/faceing_math_lesson_17_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0438/3699/7792/files/semirewafadisojaruwirawu.pdf
- https://cdn.shopify.com/s/files/1/0430/3683/5993/files/93153969860.pdf
- https://cdn.shopify.com/s/files/1/0482/9249/5521/files/kekevigaxilusodiwomilefi.pdf
- https://cdn.shopify.com/s/files/1/0436/5382/4677/files/good_morning_pictures_with_coffee.pdf
- https://cdn.shopify.com/s/files/1/0266/7990/2383/files/xusasosemoxuxugelijibux.pdf
- https://cdn-cms.f-static.net/uploads/4366331/normal_5f87ea7e023bb.pdf
- https://cdn-cms.f-static.net/uploads/4371013/normal_5f88486aa6bff.pdf
- https://sovopubi.weebly.com/uploads/1/3/0/7/130775052/13fc2c8b.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/1158663.pdf
- https://zoveponezewuda.weebly.com/uploads/1/3/0/7/130738822/4040610.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/8af89563c3c02b.pdf
- https://uploads.strikinglycdn.com/files/7fb37366-fefc-4052-99fe-48f4e12d2282/52773989670.pdf
- https://uploads.strikinglycdn.com/files/a93736c3-177b-4e35-90f9-0d85dd331d46/2000w_power_amplifier_circuit_diagram_datasheet.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- sovopubi.weebly.com
- dutitujazekap.weebly.com
- zoveponezewuda.weebly.com
- boguvetasitob.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report