SUSPICIOUS — portable_high_frequency_lz_006a.pdf
SUSPICIOUS — portable_high_frequency_lz_006a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
816a1f9b9c99e3ef1726433d329bb4e63436ee0c825671b89c47cc7f0032330b - SHA-1:
0d51ba3d478b3a4e95f2fd32c2f59f88bb9e6a7d - MD5:
33779bcb09acb30df7ce65bea2b05816 - ssdeep:
768:egGzpDepC2IveznAJhYppqtDmZziLVM8q4gbZQMwUrTQxaX5aXRNnCP:bGFKpLGwnxwV2yurkAUXRNnCP - TLSH:
T1F6327BF350A7DD8C7A879F03AAAF346D608AD348613297A4548C277CC4BC37D6E50A61 - Submitted as: portable_high_frequency_lz_006a.pdf
- File type: pdf · Size: 44464 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=portable+high+frequency+lz+006a, https://cdn-cms.f-static.net/uploads/4372104/normal_5f8b19ac30381.pdf, https://cdn-cms.f-static.net/uploads/4367281/normal_5f886150e07d0.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=portable+high+frequency+lz+006a
- https://cdn-cms.f-static.net/uploads/4372104/normal_5f8b19ac30381.pdf
- https://cdn-cms.f-static.net/uploads/4367281/normal_5f886150e07d0.pdf
- https://cdn-cms.f-static.net/uploads/4369152/normal_5f8911138514e.pdf
- https://cdn-cms.f-static.net/uploads/4379234/normal_5f8be20766708.pdf
- https://cdn-cms.f-static.net/uploads/4368227/normal_5f8bc3db26aab.pdf
- https://cdn-cms.f-static.net/uploads/4366306/normal_5f8ced43bc912.pdf
- https://cdn.shopify.com/s/files/1/0480/8209/2196/files/37251402924.pdf
- https://cdn.shopify.com/s/files/1/0438/3129/6160/files/whitneys_kiss_summary.pdf
- https://cdn.shopify.com/s/files/1/0431/5932/2778/files/poulenc_un_soir_de_neige_3.pdf
- https://cdn.shopify.com/s/files/1/0493/4772/3423/files/watch_black_swan_free_online.pdf
- https://uploads.strikinglycdn.com/files/810bd2e4-4843-4165-b1f3-15a7670a9e1b/75366337667.pdf
- https://uploads.strikinglycdn.com/files/25c540e6-41c2-430d-80aa-5b5ac6b7e33f/35132230514.pdf
- https://uploads.strikinglycdn.com/files/8b0e7386-8f57-4b24-a223-ec74ae87c2a9/27453261083.pdf
- https://uploads.strikinglycdn.com/files/4fb76475-0db3-4280-af92-6a61e2526a13/79102682324.pdf
- https://uploads.strikinglycdn.com/files/90f61cc4-8328-4481-a7e0-bf067e6fd7d1/worulagidogonusino.pdf
- https://uploads.strikinglycdn.com/files/279e91c3-cacb-448d-8f7a-8feff66bb7b9/gekusemitofovezakolesukov.pdf
- https://uploads.strikinglycdn.com/files/cb29b61e-0656-4c28-a893-f024201a29e8/53574438493.pdf
- https://uploads.strikinglycdn.com/files/ec8623eb-5d64-4aab-b75d-2923f3016d6b/tugurar.pdf
- https://nubojubixuxo.weebly.com/uploads/1/3/1/4/131410311/164842.pdf
- https://vimiwegom.weebly.com/uploads/1/3/0/7/130775837/ganepon-fadogi-nerere-dusij.pdf
- https://lagukekejase.weebly.com/uploads/1/3/0/8/130815031/4576142.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/0cbd7f35736ab.pdf
- https://rolosakuzorega.weebly.com/uploads/1/3/1/3/131379035/64eac.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- nubojubixuxo.weebly.com
- vimiwegom.weebly.com
- lagukekejase.weebly.com
- jakedekokobara.weebly.com
- rolosakuzorega.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report