SUSPICIOUS — 84561057682.pdf
SUSPICIOUS — 84561057682.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
be66022243755a34675950b982ac3b8953dadefa731c4fcd25e5a33e4b499c27 - SHA-1:
24d8fda4e5df52a8686124981251eed90691adc3 - MD5:
0092eaf709723cd3747e0dc6c06474bc - ssdeep:
768:0igGzpDU85wEncwFc4IYIdXtH9z0Pn9pDAxQhUxi1xw3gKZN97CHcOWh5:0/GFw85q4fIdV6v9hw3gKb8HVWh5 - TLSH:
T1A9329DF36097ED4C7A8A5F036EAB1099A48AD34CA137D690958C373DD0BCABD7E10950 - Submitted as: 84561057682.pdf
- File type: pdf · Size: 44328 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=aircraft+design+a+conceptual+approach+pdf+download, http://lejorutip.fullglassglazing.com/uploads/1/3/1/8/131871426/pilugojazideso.pdf, http://files.taylororrstudio.com/uploads/1/3/0/8/130813357/66e01751d1.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=aircraft+design+a+conceptual+approach+pdf+download
- http://lejorutip.fullglassglazing.com/uploads/1/3/1/8/131871426/pilugojazideso.pdf
- http://files.taylororrstudio.com/uploads/1/3/0/8/130813357/66e01751d1.pdf
- http://rurem.threesisterstudio.com/uploads/1/3/0/7/130739693/1521565.pdf
- http://relefod.renibickelyoga.com/uploads/1/3/1/3/131381540/gumidowesidar.pdf
- http://files.tanoramaofconcord.com/uploads/1/3/1/8/131871408/valutorodux.pdf
- https://cdn.shopify.com/s/files/1/0430/2848/0157/files/motokilibaledapodid.pdf
- https://cdn.shopify.com/s/files/1/0430/9902/9655/files/vakademeloxejim.pdf
- https://cdn.shopify.com/s/files/1/0437/3676/0485/files/advanced_technical_analysis_forex.pdf
- https://cdn.shopify.com/s/files/1/0431/7573/9553/files/68915569838.pdf
- https://site-1036646.mozfiles.com/files/1036646/32619299711.pdf
- https://site-1036803.mozfiles.com/files/1036803/sifefibekozefapoja.pdf
- https://site-1037878.mozfiles.com/files/1037878/39284853022.pdf
- https://site-1037266.mozfiles.com/files/1037266/xexunodapali.pdf
- https://site-1036764.mozfiles.com/files/1036764/toxipepipabuzumudipelele.pdf
- https://uploads.strikinglycdn.com/files/bd379a10-f26c-48e9-8a8d-9872c2e355fb/28806850669.pdf
- https://uploads.strikinglycdn.com/files/5c01fe97-e79a-45f3-9932-4fdf1cd4aefa/5424447904.pdf
- https://uploads.strikinglycdn.com/files/4923fc55-a858-4978-ae5e-0bd2c39fd286/6579922737.pdf
- https://uploads.strikinglycdn.com/files/b136efbe-2b56-47a4-81ce-85588d4aeea5/rosupijujunaluzigutefure.pdf
- https://uploads.strikinglycdn.com/files/533689a7-4cf4-438e-ba23-8b76f0c3d47b/73872985588.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- lejorutip.fullglassglazing.com
- files.taylororrstudio.com
- rurem.threesisterstudio.com
- relefod.renibickelyoga.com
- files.tanoramaofconcord.com
- cdn.shopify.com
- site-1036646.mozfiles.com
- site-1036803.mozfiles.com
- site-1037878.mozfiles.com
- site-1037266.mozfiles.com
- site-1036764.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report