SUSPICIOUS — 23704945728.pdf
SUSPICIOUS — 23704945728.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
9874c3b70b1c3887e53ffcc14a983b460b2bc2cb56cc6d92cbe6ebcc17384ebc - SHA-1:
a8212992fe18ac272e555baf8bcd2ebab7ec1992 - MD5:
992074802296e555f5a53e7b0de64e18 - ssdeep:
768:KGgGzpD3pzHedoT/UuCAGx7rHG8p/0NL/qRGoR7wcL3zGoifmqNhhj:kGFjpLCD/m8p8tO0cL3zGoiftNhhj - TLSH:
T16932AEF750DBED8C3AC79B03ADA62169614AC38C613797A0149C7B2CC47C2BDBD50962 - Submitted as: 23704945728.pdf
- File type: pdf · Size: 44401 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=download+new+king+james+bible+for+android, https://uploads.strikinglycdn.com/files/197ba764-739d-46de-a3c9-fbd9f12707ad/giregu.pdf, https://uploads.strikinglycdn.com/files/11ae4df4-d686-4fba-acf4-3e1e3d455fff/52751572720.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=download+new+king+james+bible+for+android
- https://uploads.strikinglycdn.com/files/197ba764-739d-46de-a3c9-fbd9f12707ad/giregu.pdf
- https://uploads.strikinglycdn.com/files/11ae4df4-d686-4fba-acf4-3e1e3d455fff/52751572720.pdf
- https://uploads.strikinglycdn.com/files/37c7f050-1117-4c84-9cbf-87f70e502146/wutezixo.pdf
- https://uploads.strikinglycdn.com/files/1de2f274-5faa-4ccf-80e5-2dab2e6088c5/zotututunudijomavumelen.pdf
- https://cdn-cms.f-static.net/uploads/4367302/normal_5f8821589d5dd.pdf
- https://cdn-cms.f-static.net/uploads/4367941/normal_5f877888c99e9.pdf
- https://cdn-cms.f-static.net/uploads/4366319/normal_5f8760ba70f56.pdf
- https://uploads.strikinglycdn.com/files/a44a3c06-14fb-4f94-ad79-5b2ed8085eed/gubeluloweb.pdf
- https://uploads.strikinglycdn.com/files/3bbc57f3-5ab6-4ae1-afbb-a99a64763256/nobolumulis.pdf
- https://cdn.shopify.com/s/files/1/0433/7762/3201/files/49570244789.pdf
- https://cdn.shopify.com/s/files/1/0438/1235/6253/files/ms_70-410_study_guide.pdf
- https://cdn.shopify.com/s/files/1/0498/5854/3771/files/velepawoj.pdf
- https://cdn.shopify.com/s/files/1/0492/2520/3868/files/french_novelists_word_whizzle.pdf
- https://uploads.strikinglycdn.com/files/ef7bddf2-7bda-49b2-86c7-4a7d508d5b47/tifuwoluvuwetujepitoni.pdf
- https://uploads.strikinglycdn.com/files/424695ab-4a4b-46bb-adb1-25f0793640bf/48334617320.pdf
- https://sepenunaxob.weebly.com/uploads/1/3/0/7/130776074/83cf03c0b574f9d.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/wogiselaruto-nokage.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/3794757.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- sepenunaxob.weebly.com
- xojerajap.weebly.com
- bedizegoresupa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report