SUSPICIOUS — 13191608162.pdf
SUSPICIOUS — 13191608162.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
8b889528fa068fe9dfce7a7a42916f4a3ddfe5281f3298886fec1bbd71818f04 - SHA-1:
8a599e487aab5700d8462e1c800260cee66eaa21 - MD5:
7255f54dd7bc13b251eb7550596faf55 - ssdeep:
768:1gGzpDqJGDxTiA9SY3UGRdzkBlpSIDtCdRNF3bX4C6djCVWBuWIRwBY:mGFueGA9SY3ldzEkRv3boCcjgauf0Y - TLSH:
T1D3328DF3519BED8CBB8AAB039DAA00586187C78C6023DA4455CC7B3CD47C6ED6E10A61 - Submitted as: 13191608162.pdf
- File type: pdf · Size: 46211 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=fashion+the+definitive+history+of+costume+and+style, https://uploads.strikinglycdn.com/files/21b4a51b-7794-40dc-bedc-8c4bee240612/40109750078.pdf, https://uploads.strikinglycdn.com/files/8884596c-65ef-4d93-9832-6717502e4334/41556134709.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=fashion+the+definitive+history+of+costume+and+style
- https://uploads.strikinglycdn.com/files/21b4a51b-7794-40dc-bedc-8c4bee240612/40109750078.pdf
- https://uploads.strikinglycdn.com/files/8884596c-65ef-4d93-9832-6717502e4334/41556134709.pdf
- https://uploads.strikinglycdn.com/files/e88aa09b-14cd-4a9f-8796-fc421c193d26/93137517855.pdf
- https://uploads.strikinglycdn.com/files/a634f951-26ea-41ac-80fa-7f9dda347db0/83071935140.pdf
- https://uploads.strikinglycdn.com/files/76941240-9f1d-4326-b5a2-a333c5eec1c6/59015018684.pdf
- https://uploads.strikinglycdn.com/files/c096ba9d-30f7-4536-90bf-5c5c6840040f/34864339251.pdf
- https://uploads.strikinglycdn.com/files/b1c2ea2f-43eb-4941-9f79-a0ad0464d323/48896392613.pdf
- https://uploads.strikinglycdn.com/files/773177cb-a770-4a75-b412-088e513bbb76/62730560796.pdf
- https://site-1036751.mozfiles.com/files/1036751/wukutidomoposazexakogat.pdf
- https://site-1042593.mozfiles.com/files/1042593/78234526234.pdf
- https://site-1038647.mozfiles.com/files/1038647/nuzelav.pdf
- https://site-1038948.mozfiles.com/files/1038948/lodewiguboferetomawexotas.pdf
- http://xidasirom.instajeepthing.com/uploads/1/3/2/3/132303079/nidarutapajebup.pdf
- http://files.margateterrapinrescue.org/uploads/1/3/0/7/130775277/panewuxeko.pdf
- http://files.candidworldreport.com/uploads/1/3/1/3/131383657/9850949.pdf
- http://zareg.trouphighchorus.com/uploads/1/3/2/6/132695478/3b2ecc741c.pdf
- http://files.annualreport-m2016.com/uploads/1/3/1/0/131070227/riregufujumiben.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1036751.mozfiles.com
- site-1042593.mozfiles.com
- site-1038647.mozfiles.com
- site-1038948.mozfiles.com
- xidasirom.instajeepthing.com
- files.margateterrapinrescue.org
- files.candidworldreport.com
- zareg.trouphighchorus.com
- files.annualreport-m2016.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report