SUSPICIOUS — 4683654_klyuchi_dlya_windows_anytime_upgrade.pdf
SUSPICIOUS — 4683654_klyuchi_dlya_windows_anytime_upgrade.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
bcbcc8d2f0a1330e25bbdd97cf9c1ff5df6d679c8652f5873a80406e68bf75e0 - SHA-1:
621521b8acda320ca266797e71d84c03322b9724 - MD5:
61071be27971f80e9f42eda23a7ae295 - ssdeep:
6144:X/gNC+0ueoFk8L8a9Sr8tDlChLbfy/h4402emF3UU9ZJMInWCvlgn7ci:vgNC3uk8lus5YyJl9rdzW7ci - TLSH:
T1D64802FACE049969DBEC3B697D2D543E2E07914110F11B2178A32AFB13B633B5305926 - Submitted as: 4683654_klyuchi_dlya_windows_anytime_upgrade.pdf
- File type: pdf · Size: 371254 bytes
- Verdict: suspicious (44/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.13
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: http://botcraftman.ru/?lip&keyword=%D0%BA%D0%BB%D1%8E%D1%87%D0%B8+%D0%B4%D0%BB%D1%8F+windows+anytime+upgrade&charset=utf-8, http://img1.liveinternet.ru/images/attach/c/6//4683/4683632_klyuchi_dlya_kis_2013_skachat_besplatno_torrent.pdf, http://img0.liveinternet.ru/images/attach/c/6//4682/4682987_zvuk_blendera.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://botcraftman.ru/?lip&keyword=%D0%BA%D0%BB%D1%8E%D1%87%D0%B8+%D0%B4%D0%BB%D1%8F+windows+anytime+upgrade&charset=utf-8
- http://img1.liveinternet.ru/images/attach/c/6//4683/4683632_klyuchi_dlya_kis_2013_skachat_besplatno_torrent.pdf
- http://img0.liveinternet.ru/images/attach/c/6//4682/4682987_zvuk_blendera.pdf
- http://img1.liveinternet.ru/images/attach/c/6//4683/4683409_skachat_papinuy_dochki_2_besplatno_bez_klyuchey_i_vremeni.pdf
Embedded domains
- botcraftman.ru
- img1.liveinternet.ru
- img0.liveinternet.ru
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report