SUSPICIOUS — 70578505953.pdf
SUSPICIOUS — 70578505953.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
bb0ca5821fc5deadb1d397d58a847a5a158ce82718ec7a37044378fcca9c0013 - SHA-1:
e85839fea7467bc4380039f4180ede21fd9cd6f2 - MD5:
a5a3846e7e3e7da8b2b3ac2ad5fe1c2d - ssdeep:
768:FgGzpDSruPAfuK46wrXmbyF9PeuHeO8xjv+aIKoOlcYi:WGFWrC3euHNGjGaIK5lcYi - TLSH:
T16731AFF3445BDCCC3E8BAB136DA6016A6186D68C71379764149A7E7CC4BC2BCBE00861 - Submitted as: 70578505953.pdf
- File type: pdf · Size: 42280 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=edit+pdf+text+and+images+free+download, http://mulere.highlanderteach.com/uploads/1/3/1/4/131406202/galejixale_wutiganeja.pdf, http://foxexaxo.chunkyharmonies.com/uploads/1/3/0/8/130813528/wuniduvi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=edit+pdf+text+and+images+free+download
- http://mulere.highlanderteach.com/uploads/1/3/1/4/131406202/galejixale_wutiganeja.pdf
- http://foxexaxo.chunkyharmonies.com/uploads/1/3/0/8/130813528/wuniduvi.pdf
- http://luzubu.telaadvisor.com/uploads/1/3/0/7/130776436/67c1bf87e9.pdf
- http://wotenulug.placercountyreviewagency.com/uploads/1/3/1/6/131636733/jiruxus.pdf
- http://risej.art2.store/uploads/1/3/2/6/132695492/8668727.pdf
- http://luvada.calciomaestro.com/uploads/1/3/1/4/131437229/xoduvasega-nodebivibinelo-fumovegava.pdf
- http://files.dietaryapothecary.com/uploads/1/3/0/8/130873728/2694707.pdf
- http://libazo.indconstructionforum.com/uploads/1/3/1/4/131438563/pozepemufepe_fibizogoriviw_kogosixo.pdf
- http://files.camillahouse.com/uploads/1/3/1/4/131482952/5298251ffd.pdf
- https://cdn.shopify.com/s/files/1/0437/1703/4134/files/words_that_rhyme_with_theme.pdf
- https://cdn.shopify.com/s/files/1/0428/8151/5673/files/39308705734.pdf
- https://cdn.shopify.com/s/files/1/0435/5463/5937/files/crossword_worksheet_with_answers.pdf
- https://cdn.shopify.com/s/files/1/0430/4021/1097/files/61467736449.pdf
- https://cdn.shopify.com/s/files/1/0435/0813/8150/files/kusoporol.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- mulere.highlanderteach.com
- foxexaxo.chunkyharmonies.com
- luzubu.telaadvisor.com
- wotenulug.placercountyreviewagency.com
- risej.art2.store
- luvada.calciomaestro.com
- files.dietaryapothecary.com
- libazo.indconstructionforum.com
- files.camillahouse.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report