SUSPICIOUS — 61539651855.pdf
SUSPICIOUS — 61539651855.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
9ff77b61f60aac299612b7c036210bd2f587d9379bdf80a1e11c6ba04e41cc4a - SHA-1:
96567c6613720437d0e54a5b291815fa320f2df4 - MD5:
779362d9a6a9c80a654f3a9c2fbb7976 - ssdeep:
768:CgGzpDRpAvDztWd1Coi/TjSTNqjKRRGJqeL1UUNzllJWz4uDkGTvZwxC2+w6w:fGFVpAbx4iiNqK2JD5UUJ3JWz4IkMh2/ - TLSH:
T16033AEF350DBDD8C7AC6AF83A5B601566146C78C31239BA059CC7BADC478ABD6F00990 - Submitted as: 61539651855.pdf
- File type: pdf · Size: 48536 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=mpow+071+usb+headset+instructions, https://uploads.strikinglycdn.com/files/36870c8c-aa6a-4480-a9e6-6848325c17df/jutimawofurobavo.pdf, https://uploads.strikinglycdn.com/files/59d5d184-9858-4c9a-9992-f4c88c2dc526/87960567910.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=mpow+071+usb+headset+instructions
- https://uploads.strikinglycdn.com/files/36870c8c-aa6a-4480-a9e6-6848325c17df/jutimawofurobavo.pdf
- https://uploads.strikinglycdn.com/files/59d5d184-9858-4c9a-9992-f4c88c2dc526/87960567910.pdf
- https://uploads.strikinglycdn.com/files/715382d4-1427-42b1-ad52-fc6e31199407/905024776.pdf
- https://uploads.strikinglycdn.com/files/1dceaeeb-a87d-44db-9c96-b46f765bd8be/20479730057.pdf
- https://uploads.strikinglycdn.com/files/3c38029f-25ff-4153-88ce-c1dec0a92990/zosev.pdf
- https://uploads.strikinglycdn.com/files/236d1fee-642d-4cac-881b-c63d8534584a/59441777666.pdf
- https://uploads.strikinglycdn.com/files/769ad6c4-1cc5-4329-8699-16066a7bf49a/pisemixenitizumi.pdf
- https://uploads.strikinglycdn.com/files/417024eb-8066-4789-bc75-d924358e8999/duzonafaminexunosomomumak.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/665612.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/f5d445.pdf
- https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/a7b88.pdf
- https://cdn.shopify.com/s/files/1/0481/7751/2597/files/navy_seals_vietnam_missions.pdf
- https://cdn.shopify.com/s/files/1/0498/7555/0369/files/4106320028.pdf
- https://cdn.shopify.com/s/files/1/0479/2116/8540/files/17475189687.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- dutitujazekap.weebly.com
- mogilifus.weebly.com
- gevafitasib.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report