SUSPICIOUS — sara_rola_patli_kamar_ka_mp4_video_download.pdf
SUSPICIOUS — sara_rola_patli_kamar_ka_mp4_video_download.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
68c4312740897d44d1181d6c8e315bda967ebfb31521fd5e996d19e14839f0a7 - SHA-1:
3a0892ed94b67b859345236bd4d76fe9d223f397 - MD5:
7e98128fa56362bdbc356857f9f37891 - ssdeep:
768:mKgGzpDPezuzJU63IG87eAl2Ja1wR48mas9066YsB1aaA1IPiICWc23fGDGDqE:kGFjeIK9J6YsBIa8J9WcKGDKqE - TLSH:
T1EF328EF31097DCCC7A8BAB03A9E6149A754ACB896126E75004897B3CD47C7FD6F00A64 - Submitted as: sara_rola_patli_kamar_ka_mp4_video_download.pdf
- File type: pdf · Size: 46334 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=sara+rola+patli+kamar+ka+mp4+video+download, https://cdn.shopify.com/s/files/1/0495/5255/6184/files/27807444273.pdf, https://cdn.shopify.com/s/files/1/0440/7777/7061/files/97110684721.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=sara+rola+patli+kamar+ka+mp4+video+download
- https://cdn.shopify.com/s/files/1/0495/5255/6184/files/27807444273.pdf
- https://cdn.shopify.com/s/files/1/0440/7777/7061/files/97110684721.pdf
- https://cdn.shopify.com/s/files/1/0439/1347/8312/files/zegotefisexev.pdf
- https://cdn-cms.f-static.net/uploads/4370268/normal_5f894f0f8809f.pdf
- https://cdn-cms.f-static.net/uploads/4366034/normal_5f88dea88ebcb.pdf
- https://cdn-cms.f-static.net/uploads/4370785/normal_5f882b2fe598b.pdf
- https://cdn-cms.f-static.net/uploads/4365626/normal_5f875fc0dd4c1.pdf
- https://cdn-cms.f-static.net/uploads/4366965/normal_5f8b19bd3e160.pdf
- https://cdn.shopify.com/s/files/1/0440/7777/7061/files/nabugajegatikegugedavebes.pdf
- https://cdn.shopify.com/s/files/1/0483/5603/2665/files/compound_inequalities_worksheet_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0437/7831/0295/files/polk_rti_a7_crossover.pdf
- https://cdn.shopify.com/s/files/1/0437/1087/3750/files/14471203623.pdf
- https://cdn.shopify.com/s/files/1/0481/5916/2521/files/28252391586.pdf
- https://cdn.shopify.com/s/files/1/0496/8595/4716/files/soil_forming_factors.pdf
- https://cdn-cms.f-static.net/uploads/4380887/normal_5f8b77e68073c.pdf
- https://cdn-cms.f-static.net/uploads/4369927/normal_5f8894a176dd1.pdf
- https://cdn.shopify.com/s/files/1/0477/3294/9148/files/godopu.pdf
- https://cdn.shopify.com/s/files/1/0430/0747/5875/files/pruning_made_easy_peter_mchoy.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report