SUSPICIOUS — 74816489028.pdf
SUSPICIOUS — 74816489028.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
7d63d8c2b7db44c14f16cc13b9933a4701eabb1202291e982c72caf2c4ad4ace - SHA-1:
f87154855c66f754ffce6481f07fed4d8b30f40e - MD5:
d6e637e750c51744b8d2b660febdd91c - ssdeep:
768:9gGzpDCQ9PuOzQfQVjZw01IVDVELWU08AbRSkXFPm6/4WYZBZFVnpCGcx5RQd34d:+GFeeIgYRZ1Px+lmRUWF+kpAvk8p2 - TLSH:
T13934BEF35097ED4CBB8A5B13A9F72059A089D3487336C764048C763CE5AC6FE6E119A0 - Submitted as: 74816489028.pdf
- File type: pdf · Size: 57533 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=review+samsung+note+9, https://cdn-cms.f-static.net/uploads/4366385/normal_5f9355e6dd6c5.pdf, https://cdn-cms.f-static.net/uploads/4387218/normal_5f8e0e71e7966.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=review+samsung+note+9
- https://cdn-cms.f-static.net/uploads/4366385/normal_5f9355e6dd6c5.pdf
- https://cdn-cms.f-static.net/uploads/4387218/normal_5f8e0e71e7966.pdf
- https://cdn-cms.f-static.net/uploads/4386347/normal_5f934867b8f86.pdf
- https://cdn-cms.f-static.net/uploads/4407780/normal_5f933fa86c81a.pdf
- https://cdn-cms.f-static.net/uploads/4366302/normal_5f87eafe22b3a.pdf
- https://uploads.strikinglycdn.com/files/c518c8e6-7207-4e2e-95c5-7fd521c6dedf/gidirolejojojamuviw.pdf
- https://uploads.strikinglycdn.com/files/39167e3d-5bac-4d07-8728-101b0876b41b/353787974.pdf
- https://cdn.shopify.com/s/files/1/0429/4456/1319/files/interval_training_app_android.pdf
- https://cdn.shopify.com/s/files/1/0496/6088/7193/files/puvujiketabomu.pdf
- https://cdn.shopify.com/s/files/1/0496/5321/9479/files/standard_form_questions_and_answers.pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/honda_ecm_2800_manual.pdf
- https://cdn.shopify.com/s/files/1/0434/9257/3336/files/81276731994.pdf
- https://norumevi.weebly.com/uploads/1/3/0/9/130969469/xezomomob-sesuwuriz-judesopagu.pdf
- https://gozofuma.weebly.com/uploads/1/3/0/8/130874065/719390.pdf
- https://netaluzubik.weebly.com/uploads/1/3/0/8/130813777/5ef07c25ec89c5b.pdf
- https://tubenuluni.weebly.com/uploads/1/3/1/4/131437864/391d9f195a0c8.pdf
- https://gejatovuri.weebly.com/uploads/1/3/1/4/131406669/ec797.pdf
- https://s3.amazonaws.com/jovekus/yj_axis_cube_solution.pdf
- https://s3.amazonaws.com/henghuili-files/curriculum_vitae_format_download_romana.pdf
- https://s3.amazonaws.com/pazifetanegapu/pdf_read_aloud_app_for_ipad.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- norumevi.weebly.com
- gozofuma.weebly.com
- netaluzubik.weebly.com
- tubenuluni.weebly.com
- gejatovuri.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report