SUSPICIOUS — 74015596658.pdf
SUSPICIOUS — 74015596658.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
6ffabee8eb4b84fcca3dc36a76d3aaf1c295607e28db7a4f0fb5d0c0d5b68880 - SHA-1:
5eebd008718709ff7641ca985bec4fc46c4c74e5 - MD5:
3cdfcc370b0c23f978a031a3f31c9656 - ssdeep:
768:FgGzpDv6pZOsKXh0nzbPf0xwtOogfo1qlW8GMYf8QEC29yT+PJgTo:WGFDST/sWtulRD90mJgTo - TLSH:
T1BF32BEF3919BDD4CBA867F03AEB20589A286C78C602756A455CC7B3D807C5BDAE00D61 - Submitted as: 74015596658.pdf
- File type: pdf · Size: 43465 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=boeing+737-+300+specifications+pdf, https://uploads.strikinglycdn.com/files/7c463ee6-1243-4a33-955c-362ad43d8b1b/87422472349.pdf, https://uploads.strikinglycdn.com/files/11011a4a-fab5-4b01-b903-7abb80382b54/65544189807.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=boeing+737-+300+specifications+pdf
- https://uploads.strikinglycdn.com/files/7c463ee6-1243-4a33-955c-362ad43d8b1b/87422472349.pdf
- https://uploads.strikinglycdn.com/files/11011a4a-fab5-4b01-b903-7abb80382b54/65544189807.pdf
- https://uploads.strikinglycdn.com/files/7e64a92c-452c-42b1-9663-ed96c9c6a2f5/sopaj.pdf
- https://uploads.strikinglycdn.com/files/024bfb57-b1df-412e-80a8-223a39f38166/35524032128.pdf
- https://uploads.strikinglycdn.com/files/efd7b087-4904-416f-b71a-96f1bb0fa9f8/bigapuvas.pdf
- http://voxilimep.charteredengineers.org/uploads/1/3/0/9/130969586/3743633.pdf
- http://lolojil.skyfieldtropical.com/uploads/1/3/1/3/131383591/mokosobuwukibis-fifodet-pubix.pdf
- http://zepagomoz.psusdhistory.us/uploads/1/3/1/4/131438188/bodexavalarubi.pdf
- https://uploads.strikinglycdn.com/files/512bd909-2707-4f01-9d0e-94b6a2f30c19/44525502871.pdf
- https://uploads.strikinglycdn.com/files/4abd4b11-5e8d-474a-8723-c92e160c1fbd/gelew.pdf
- https://uploads.strikinglycdn.com/files/ab5f4778-b5e4-43fb-abff-432457c3c94a/wizovigezota.pdf
- https://site-1037172.mozfiles.com/files/1037172/masaxisubowatopubon.pdf
- https://site-1042092.mozfiles.com/files/1042092/58512182737.pdf
- https://site-1037138.mozfiles.com/files/1037138/76365500559.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- voxilimep.charteredengineers.org
- lolojil.skyfieldtropical.com
- zepagomoz.psusdhistory.us
- site-1037172.mozfiles.com
- site-1042092.mozfiles.com
- site-1037138.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report