SUSPICIOUS — dinaxexibela.pdf
SUSPICIOUS — dinaxexibela.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
bba9315a198f538cfb58a418947836b31aef0031791e2c6911972ccb50e0a9dc - SHA-1:
00824edb68e9a5c7608059692a7dc4e3b84355d2 - MD5:
76fe7e634f0caf65256c3ff3d0a3239a - ssdeep:
768:xgGzpD7jimJ/q4IZEU8+guNUhCeJvL8xzdClnv1b1tOozWH12NsRACsMYuGFlr7t:CGFPj6RaIMwGv1580WH1rANuGFh7Ye - TLSH:
T1D6329EF350A7DE8C7A8ADB135EF7159D608A93896032666414CC77ACD4BC2FE2E10960 - Submitted as: dinaxexibela.pdf
- File type: pdf · Size: 46172 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://trafftec.ru/wb?keyword=lamp%20words%20for%20life%20app%20free, https://uploads.strikinglycdn.com/files/65acc80e-058e-4ffd-8724-88db13fa6e9c/32926108638.pdf, https://cdn-cms.f-static.net/uploads/4386594/normal_5f8fa32116831.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafftec.ru/wb?keyword=lamp%20words%20for%20life%20app%20free
- https://uploads.strikinglycdn.com/files/65acc80e-058e-4ffd-8724-88db13fa6e9c/32926108638.pdf
- https://cdn-cms.f-static.net/uploads/4386594/normal_5f8fa32116831.pdf
- https://cdn-cms.f-static.net/uploads/4370299/normal_5f9d0248da2b9.pdf
- https://cdn-cms.f-static.net/uploads/4373016/normal_5f92903b915bd.pdf
- https://uploads.strikinglycdn.com/files/709d09fc-a646-462b-97a5-0f98c0219745/vatelenigotofisutuf.pdf
- https://s3.amazonaws.com/zategafozasiru/because_you_loved_me_chords.pdf
- https://uploads.strikinglycdn.com/files/8c93c957-bf52-4ef6-8eec-3c2eacbd9dd9/zafefuza.pdf
- https://cdn-cms.f-static.net/uploads/4447464/normal_5fa64770a33bc.pdf
- https://uploads.strikinglycdn.com/files/a433d9fa-9011-4194-bd63-61c69cc3eb95/ultrastat_thermostat_user_manual.pdf
- https://s3.amazonaws.com/kudowo/29014606662.pdf
- https://uploads.strikinglycdn.com/files/0083376f-7a82-49bd-a2f3-34f7f4e50ef0/vagedusuluna.pdf
- https://cdn-cms.f-static.net/uploads/4379856/normal_5f8f7319adec5.pdf
- https://uploads.strikinglycdn.com/files/8e3b9a91-8acc-4a95-99cd-329770c23fee/tamales_calientitos_mp3_songs.pdf
- https://uploads.strikinglycdn.com/files/563de7d8-6a32-4f28-b4af-bfafac784e63/86197703264.pdf
- https://cdn-cms.f-static.net/uploads/4465136/normal_5fa7c50480028.pdf
- https://cdn-cms.f-static.net/uploads/4409118/normal_5fa47cc063096.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafftec.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report