SUSPICIOUS — 40677895329.pdf
SUSPICIOUS — 40677895329.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
b29fefa3a6145fbdf7916a4c81323a184cd76505b1720c2c666dd48a0ac07938 - SHA-1:
2f1480e0279bd728216602b0d57fe2bf8bdfaec7 - MD5:
9f43ade581dfeb842bd1c48a90ff424c - ssdeep:
768:OgGzpDX3Tuv/jsATWZ+hMp/DhpSkdBEiEQdXLmIbNV+LBtIEcGZv5:rGFj3GwA6YOp/bZdpEQdXCyT+t7Zv5 - TLSH:
T13632AFF340A7ED4C7B8BAB1369F6141D508AD68D7133E2A459D8776CC4BCABC6E00A11 - Submitted as: 40677895329.pdf
- File type: pdf · Size: 44612 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=pm+ehsas+program+scholarship+form, https://site-1036753.mozfiles.com/files/1036753/44322346836.pdf, https://site-1039840.mozfiles.com/files/1039840/58612050860.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=pm+ehsas+program+scholarship+form
- https://site-1036753.mozfiles.com/files/1036753/44322346836.pdf
- https://site-1039840.mozfiles.com/files/1039840/58612050860.pdf
- https://site-1036902.mozfiles.com/files/1036902/lufokokobuwupavi.pdf
- https://site-1037152.mozfiles.com/files/1037152/85558347420.pdf
- https://site-1036626.mozfiles.com/files/1036626/50579713628.pdf
- https://cdn.shopify.com/s/files/1/0434/3706/4354/files/19877753190.pdf
- https://cdn.shopify.com/s/files/1/0437/1143/0809/files/76560773145.pdf
- http://jolel.mercerlanecollective.com/uploads/1/3/2/7/132740228/menefetaxajuvowal.pdf
- http://files.mrnicecream.us/uploads/1/3/1/0/131070604/pagogi.pdf
- http://files.teampixiedust.com/uploads/1/3/0/9/130968920/kobowaganulita-paboluwiromozuk.pdf
- http://files.xjrichert.com/uploads/1/3/1/3/131380288/d39c4e1e.pdf
- https://uploads.strikinglycdn.com/files/285079fc-0f56-4221-a2f0-c0d82aef646d/90921544813.pdf
- https://uploads.strikinglycdn.com/files/05b30a0d-d48b-47a0-a519-83e53b585c66/mebokiredogunijadirolunim.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1036753.mozfiles.com
- site-1039840.mozfiles.com
- site-1036902.mozfiles.com
- site-1037152.mozfiles.com
- site-1036626.mozfiles.com
- cdn.shopify.com
- jolel.mercerlanecollective.com
- files.mrnicecream.us
- files.teampixiedust.com
- files.xjrichert.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report