SUSPICIOUS — 17915730217.pdf
SUSPICIOUS — 17915730217.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
9fd20cceb7cb93e6fb98110c4d933a963e0c6a78a275750308c91191a1ff7e28 - SHA-1:
b3ab69245c1e03bc4bc77ad53ac53b2d43660c92 - MD5:
31bf3aa105a16a24a7a14d6b31847404 - ssdeep:
768:QgGzpDqp+RT4Rsj3pJs7n0MxfkYs7Snh+wx:9GF2p+R8Rsj33EfkvGnQwx - TLSH:
T16D308EF36127EC8C7A8A6F03ADE21455A14ACB4D6132976054D87B7CC4BC6FE7D40A21 - Submitted as: 17915730217.pdf
- File type: pdf · Size: 38377 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=trane+error+code+104, https://uploads.strikinglycdn.com/files/e8109578-1fad-4c74-baf1-63684673a967/77878719183.pdf, https://uploads.strikinglycdn.com/files/701c9f91-5aa9-4e35-80b5-6f70895c0f56/peselepokoziwakonewexus.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=trane+error+code+104
- https://uploads.strikinglycdn.com/files/e8109578-1fad-4c74-baf1-63684673a967/77878719183.pdf
- https://uploads.strikinglycdn.com/files/701c9f91-5aa9-4e35-80b5-6f70895c0f56/peselepokoziwakonewexus.pdf
- https://uploads.strikinglycdn.com/files/8f5dfa85-c1f3-450c-8fb9-3b9f0f3c0af1/7668113291.pdf
- https://uploads.strikinglycdn.com/files/afb5acd7-7186-47b9-87dc-7f8518838881/56403383158.pdf
- https://cdn.shopify.com/s/files/1/0430/9575/2858/files/39162514626.pdf
- https://cdn.shopify.com/s/files/1/0430/0426/4602/files/paladin_classic_wow_talents.pdf
- http://tudax.drjules.com/uploads/1/3/2/7/132741508/37eca0589add6e.pdf
- http://files.cinematasmoviemadness.com/uploads/1/3/1/3/131380337/finekuvodir_nabawobiriz_xomokadimenim.pdf
- http://meduvuwe.saintjosephsculturalcenter.org/uploads/1/3/1/3/131380600/bogixuxi.pdf
- http://rarazuga.waterkeepersiraq.org/uploads/1/3/1/4/131409090/sikisofexuvefebedix.pdf
- https://site-1038924.mozfiles.com/files/1038924/86866123048.pdf
- https://site-1043203.mozfiles.com/files/1043203/35454577585.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- tudax.drjules.com
- files.cinematasmoviemadness.com
- meduvuwe.saintjosephsculturalcenter.org
- rarazuga.waterkeepersiraq.org
- site-1038924.mozfiles.com
- site-1043203.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report