SUSPICIOUS — detet.pdf
SUSPICIOUS — detet.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
7cbde85f3679c13da7983d579b2d51d4575638f69fb161d1cd6b1798ec559a99 - SHA-1:
1bc8dd4d848cbd43074cb2b0ddd594970191e052 - MD5:
a9e0571d87046cf06e301068f2d99647 - ssdeep:
768:egGzpDWezYQDZ68HDjH2fTTNOuVAcAnzvu4q/qf2JlMRhgfBTdkDdZO0W:bGFSe0T3AcAnzvu1ifnRhgf3kDdZO0W - TLSH:
T1A3329DF3509BDD8C7ACA9F53A9FB2119654AD78C2132DBA0448C772CC4BC2BD6E40960 - Submitted as: detet.pdf
- File type: pdf · Size: 46654 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=ven+di+sal+haz+ten+weapons, https://cdn-cms.f-static.net/uploads/4366664/normal_5f8776d82743b.pdf, https://cdn-cms.f-static.net/uploads/4377414/normal_5f8a11c4c97ca.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=ven+di+sal+haz+ten+weapons
- https://cdn-cms.f-static.net/uploads/4366664/normal_5f8776d82743b.pdf
- https://cdn-cms.f-static.net/uploads/4377414/normal_5f8a11c4c97ca.pdf
- https://cdn-cms.f-static.net/uploads/4370746/normal_5f898843a08e7.pdf
- https://cdn-cms.f-static.net/uploads/4373769/normal_5f89c207c7fde.pdf
- https://cdn-cms.f-static.net/uploads/4378161/normal_5f8a861cee5b2.pdf
- https://cdn.shopify.com/s/files/1/0503/6575/9675/files/root_checker_pro_mod_apk.pdf
- https://cdn.shopify.com/s/files/1/0497/3880/9498/files/41601404795.pdf
- https://cdn-cms.f-static.net/uploads/4367947/normal_5f88f06ab5c9d.pdf
- https://cdn-cms.f-static.net/uploads/4367310/normal_5f89543428f5d.pdf
- https://cdn-cms.f-static.net/uploads/4370987/normal_5f89464d27350.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/wotareropajewub.pdf
- https://wuwuleli.weebly.com/uploads/1/3/1/3/131398564/3ca61bd.pdf
- https://vunixumo.weebly.com/uploads/1/3/1/4/131453253/pizudi.pdf
- https://vuzevarezevarot.weebly.com/uploads/1/3/0/7/130740461/0e0cd.pdf
- https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/1969782.pdf
- https://xawuwotogot.weebly.com/uploads/1/3/2/6/132695388/5717493.pdf
- https://uploads.strikinglycdn.com/files/2b4e4f85-05e0-4996-9438-87bf1d0ae790/migigogazisuwitenigule.pdf
- https://uploads.strikinglycdn.com/files/9ec0efca-3066-4b9a-8d5f-e6fafe8c55e2/vitirenemaxepokemerezi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- gimejexoxixaza.weebly.com
- wuwuleli.weebly.com
- vunixumo.weebly.com
- vuzevarezevarot.weebly.com
- babikovinemixe.weebly.com
- xawuwotogot.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report