SUSPICIOUS — 68870487406.pdf
SUSPICIOUS — 68870487406.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
b44087aada63844d030f13ccca31cc365ac768f2bdbf5d86258425ef2d5fc5f5 - SHA-1:
bd1b59cc2835c0dee17ac0bd7749c01725fde245 - MD5:
007341885f3b671e3c3844b695e1fe3d - ssdeep:
1536:bGFHH+Lkbck3lzrPYXa1aejgiN3vyDLhbDt1W:6FH8+t1zrQXa1XjgiN3+LtDy - TLSH:
T15834AEF34097EC8C7A0F2B935EBB0556B0D696896526976009CCAB6CC47C3AC7F20D91 - Submitted as: 68870487406.pdf
- File type: pdf · Size: 56274 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=%25D1%2584%25D0%25BD%25D0%25B0%25D1%2584+%25D0%25B2%25D0%25BE%25D1%2580%25D0%25BB%25D0%25B4+%25D1%2581%25D0%25BA%25D0%25B0%25D1%2587%25D0%25B0%25D1%2582%25D1%258C+%25D0%25B1%25D0%25B5%25D1%2581%25D0%25BF%25D0%25BB%25D0%25B0%25D1%2582%25D0%25BD%25D0%25BE+%25D0%25BD%25D0%25B0+%25D0%25BF%25D0%25BA+%25D0%25BD, http://files.simplygoatsmilk.com/uploads/1/3/0/8/130814717/zixivuve_xivobuxi.pdf, http://files.avedaluzern.com/uploads/1/3/2/6/132682530/ba3666ff42a81e8.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=%25D1%2584%25D0%25BD%25D0%25B0%25D1%2584+%25D0%25B2%25D0%25BE%25D1%2580%25D0%25BB%25D0%25B4+%25D1%2581%25D0%25BA%25D0%25B0%25D1%2587%25D0%25B0%25D1%2582%25D1%258C+%25D0%25B1%25D0%25B5%25D1%2581%25D0%25BF%25D0%25BB%25D0%25B0%25D1%2582%25D0%25BD%25D0%25BE+%25D0%25BD%25D0%25B0+%25D0%25BF%25D0%25BA+%25D0%25BD
- http://files.simplygoatsmilk.com/uploads/1/3/0/8/130814717/zixivuve_xivobuxi.pdf
- http://files.avedaluzern.com/uploads/1/3/2/6/132682530/ba3666ff42a81e8.pdf
- http://files.ondrashturek.com/uploads/1/3/1/6/131636914/27df6.pdf
- http://kekadobi.amerishop.biz/uploads/1/3/2/8/132814930/ee386a33e39.pdf
- http://zafix.dance4joy.info/uploads/1/3/1/4/131482975/pafawurutod.pdf
- https://cdn.shopify.com/s/files/1/0434/8814/9654/files/51007491493.pdf
- https://cdn.shopify.com/s/files/1/0466/6494/1733/files/zigikibebuwideda.pdf
- https://cdn.shopify.com/s/files/1/0483/8673/6286/files/fikofazixewewexafu.pdf
- http://files.upclothingline.com/uploads/1/3/1/3/131381675/mawemeg.pdf
- http://puwewuvas.goblinbaby.com/uploads/1/3/0/9/130969465/4208922.pdf
- http://dejeg.deenasaundersgreen.com/uploads/1/3/1/6/131637309/ribufibipif.pdf
- http://redipinol.obchaymarket.org/uploads/1/3/1/6/131636587/fdd2dfc95e9b7.pdf
- https://uploads.strikinglycdn.com/files/6449840a-7619-4f0b-beb5-8e03d1c63e44/67269921412.pdf
- https://uploads.strikinglycdn.com/files/cd927583-3dfa-4530-997b-8d78670e2f11/xotarenijazo.pdf
- https://uploads.strikinglycdn.com/files/6d105b35-7c26-4750-a017-5da75a557670/zipamexiririrekaketaro.pdf
- https://uploads.strikinglycdn.com/files/7f42c90b-d1d5-4b18-b4ee-7b5b2f23166e/28376371881.pdf
- https://uploads.strikinglycdn.com/files/a58552fe-4013-4730-a12e-8371e8cfad8d/lelafefavitirato.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- files.simplygoatsmilk.com
- files.avedaluzern.com
- files.ondrashturek.com
- kekadobi.amerishop.biz
- zafix.dance4joy.info
- cdn.shopify.com
- files.upclothingline.com
- puwewuvas.goblinbaby.com
- dejeg.deenasaundersgreen.com
- redipinol.obchaymarket.org
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report