SUSPICIOUS — 30241922381.pdf
SUSPICIOUS — 30241922381.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
98bedea9de31752c604f5bf8aadf529dcc8abd1312533fc0382c73edb862e851 - SHA-1:
715d55d5a8dd67f9b7894c9a20acb31f9bc823d0 - MD5:
3e6761b52f0ecea4e1f2ca3bc995edae - ssdeep:
768:6cgGzpDnReNB0xZ9GhYdr5+yJ0N9BIvt46a1NPHU1HpOKrrdZdw1g4KLn013hrk3:qGFDuaNwXBca1N8HEKrrdZdw1gnL0fry - TLSH:
T114329EF31063EC8C7A9A5F03BEAA105E6546C7887136A7A049C8762CD87C7FD7D41A60 - Submitted as: 30241922381.pdf
- File type: pdf · Size: 47432 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=paracetamol+infantil+bula+pdf, https://uploads.strikinglycdn.com/files/b26ff33f-6bb2-454d-8ffd-259ee6bf25f5/masedebegixikajobomibuj.pdf, https://uploads.strikinglycdn.com/files/b3167c62-bf67-4d48-b8a4-ba15876fd787/fadajukoxujesero.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=paracetamol+infantil+bula+pdf
- https://uploads.strikinglycdn.com/files/b26ff33f-6bb2-454d-8ffd-259ee6bf25f5/masedebegixikajobomibuj.pdf
- https://uploads.strikinglycdn.com/files/b3167c62-bf67-4d48-b8a4-ba15876fd787/fadajukoxujesero.pdf
- https://uploads.strikinglycdn.com/files/4f7c4595-bbbf-414c-80f7-dc91040b5c0c/nepavigapitagat.pdf
- https://uploads.strikinglycdn.com/files/617523cd-d270-4794-acec-76918234b780/37006984175.pdf
- https://uploads.strikinglycdn.com/files/bbc4646b-3085-4922-858d-f057d6cc5aa0/86790098857.pdf
- http://jodaxiw.impulsivelust.com/uploads/1/3/0/8/130814187/dereruna-gesemikevuwo-nevoz-vonomarono.pdf
- http://godiw.peteaturner.com/uploads/1/3/0/7/130776083/bc52adfd192aa.pdf
- http://jexukeje.underwateradventures.net/uploads/1/3/0/7/130738962/gibewikuv.pdf
- http://wixozo.benbrixey.com/uploads/1/3/1/3/131380601/jetuko_lewixig_tutut_lurixusidajefo.pdf
- http://files.toolstorm.ca/uploads/1/3/1/8/131871642/2910bfdf3afe632.pdf
- https://cdn.shopify.com/s/files/1/0429/8054/0575/files/navy_leave_instruction_2019.pdf
- https://cdn.shopify.com/s/files/1/0437/7044/5982/files/3222163945.pdf
- https://cdn.shopify.com/s/files/1/0436/0830/9923/files/irrigacion_de_la_arteria_cerebral_media.pdf
- https://cdn.shopify.com/s/files/1/0457/7093/2390/files/33397850313.pdf
- https://cdn.shopify.com/s/files/1/0439/0731/7912/files/pdf_to_word_online_job.pdf
- https://cdn.shopify.com/s/files/1/0482/6185/7441/files/64480845795.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- jodaxiw.impulsivelust.com
- godiw.peteaturner.com
- jexukeje.underwateradventures.net
- wixozo.benbrixey.com
- files.toolstorm.ca
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report