SUSPICIOUS — 9704624657.pdf
SUSPICIOUS — 9704624657.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
a34c5e4af20a13ef5f6d14d2fe96eba6046bce541a8425ad3e307558521b8e55 - SHA-1:
203b5d9eea2795a500e3f10d9673e7f16e65c20d - MD5:
2a3fabb60a76d9c65d3dc49fbdde9b1e - ssdeep:
768:6gGzpDf0YYZvO4g1bC9y8M0k+JQ1lo+XE8E4D2GugOZWhCpI9qy7qSRVNL:nGFzI3MTttESD2XBZWKI9VqSRVNL - TLSH:
T195329DF70097DD8C77CBAB0399E614A9954AC78E2032A6A444897B2CC47C7EDAF10971 - Submitted as: 9704624657.pdf
- File type: pdf · Size: 46346 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=ear+training+pdf, https://site-1043607.mozfiles.com/files/1043607/wevagebejelusorofijajagom.pdf, https://site-1048176.mozfiles.com/files/1048176/70929374023.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=ear+training+pdf
- https://site-1043607.mozfiles.com/files/1043607/wevagebejelusorofijajagom.pdf
- https://site-1048176.mozfiles.com/files/1048176/70929374023.pdf
- https://site-1039668.mozfiles.com/files/1039668/burumox.pdf
- https://site-1039666.mozfiles.com/files/1039666/74970885443.pdf
- https://site-1036750.mozfiles.com/files/1036750/sakevogezi.pdf
- http://files.eriktjohnson.net/uploads/1/3/2/8/132815183/mifafepoj-puxezuz-morigelib.pdf
- http://rofepudiv.mtcarmelchristianacademy.org/uploads/1/3/0/8/130813030/285d8436a68e7c.pdf
- https://uploads.strikinglycdn.com/files/1266d638-6be8-4938-800d-85f0e31adbdd/3696440449.pdf
- https://uploads.strikinglycdn.com/files/0a0ba0ce-0406-499b-99d8-fb32f0401c39/bawomokifokozuduvina.pdf
- https://uploads.strikinglycdn.com/files/59674e6f-4e27-42a3-baf6-e030fec348ee/temagavenixagisigane.pdf
- http://files.celebrateglutenfree.com/uploads/1/3/0/7/130739158/7457201.pdf
- http://files.shellfishermen.org/uploads/1/3/1/8/131871618/nimopotiwot_fitex_nijofojepo_taverixinakera.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1043607.mozfiles.com
- site-1048176.mozfiles.com
- site-1039668.mozfiles.com
- site-1039666.mozfiles.com
- site-1036750.mozfiles.com
- files.eriktjohnson.net
- rofepudiv.mtcarmelchristianacademy.org
- uploads.strikinglycdn.com
- files.celebrateglutenfree.com
- files.shellfishermen.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report