SUSPICIOUS — 70217003605.pdf
SUSPICIOUS — 70217003605.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
610ec1a1f02bd9c1abd232d0ba6ed450b0313503234d60ad9c213ae4a2bc5c8c - SHA-1:
e26bd9b1cbb7cb8016c8171003f63c5fc657ae4a - MD5:
ae722f8224dc4bae295b1112f4b9c854 - ssdeep:
768:73gGzpDBbLud9d/tWlxmU0xgkrMlWQ5mfp+Y+GRtCLQCVMv+2+v/3H:0GFtbqgkEWQUfUvGRYLQCVBbv/3H - TLSH:
T1BB307CF350A7EC8C7ACB9B03ACA615656488C7886133E36059DC776CD5BC2BDBE10861 - Submitted as: 70217003605.pdf
- File type: pdf · Size: 38224 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=cutting+edge+upper+intermediate+third+edition+workbook+answer+key+pdf, https://cdn.shopify.com/s/files/1/0429/8843/7655/files/thendral_tamil_magazine.pdf, https://cdn.shopify.com/s/files/1/0433/5091/7269/files/diablo_2_magic_find_guide.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: js, uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=cutting+edge+upper+intermediate+third+edition+workbook+answer+key+pdf
- https://cdn.shopify.com/s/files/1/0429/8843/7655/files/thendral_tamil_magazine.pdf
- https://cdn.shopify.com/s/files/1/0429/6055/2085/files/12428705126.pdf
- https://cdn.shopify.com/s/files/1/0433/5091/7269/files/diablo_2_magic_find_guide.pdf
- https://cdn.shopify.com/s/files/1/0481/1581/0457/files/46220876046.pdf
- https://cdn.shopify.com/s/files/1/0439/0001/0664/files/nosaki.pdf
- https://cdn.shopify.com/s/files/1/0434/7055/3238/files/thank_you_for_being_late_book.pdf
- https://cdn.shopify.com/s/files/1/0437/2027/8171/files/vutotubimumadakut.pdf
- https://cdn.shopify.com/s/files/1/0484/1485/1240/files/turn_pool_table_into_dining_table.pdf
- http://files.pittsburghfisherhouse.org/uploads/1/3/0/7/130740419/sezupujututina.pdf
- http://files.nicolevictoriaart.com/uploads/1/3/1/4/131453615/notisiva_wolibab_vejokevuze.pdf
- http://files.justyna-miszkiewicz.com/uploads/1/3/0/7/130739119/mitenereboguro.pdf
- http://files.dlrconstructionco.com/uploads/1/3/0/7/130739542/970fc07.pdf
- http://vemewewo.dmuenter.com/uploads/1/3/1/3/131384401/danetoso-zenojek-pavutexer.pdf
- http://vojijiku.troyelementaryspanish.com/uploads/1/3/1/6/131637881/lejositeturusejubelo.pdf
- http://jusanu.swiminfoct.com/uploads/1/3/2/8/132814930/17f68fdd.pdf
- http://files.ourhousecallvet.net/uploads/1/3/1/8/131857071/semosi-kimixasobal-baxokuw.pdf
- http://files.louthlasers.com/uploads/1/3/2/7/132740285/4262081.pdf
- http://files.kickitlivingweekly.com/uploads/1/3/0/7/130739530/49f2d3.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- files.pittsburghfisherhouse.org
- files.nicolevictoriaart.com
- files.justyna-miszkiewicz.com
- files.dlrconstructionco.com
- vemewewo.dmuenter.com
- vojijiku.troyelementaryspanish.com
- jusanu.swiminfoct.com
- files.ourhousecallvet.net
- files.louthlasers.com
- files.kickitlivingweekly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report