SUSPICIOUS — 29702915933.pdf
SUSPICIOUS — 29702915933.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
bfbbbbe82cc3f06b6ad7a654b426f4a5830080a1b6f5db2ddc4e503fc72ff875 - SHA-1:
2924188832ca24fc20bb3c34e4c4753d716d50c8 - MD5:
ffd9a0d0ebad39965533789ac5116d9e - ssdeep:
768:mgGzpDz0k0YF1XWqqDPQZsNiITv2YOsS5F97Njgdo5eBjW+:zGF/2D4ZoTFObF9cBjX - TLSH:
T12E318DF31057EDCC7AC7AB47ADB614996089D7896032D6A419887B3CC47C7BD2E40AA0 - Submitted as: 29702915933.pdf
- File type: pdf · Size: 40219 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=bcnc+tutorial+pdf, https://uploads.strikinglycdn.com/files/2c2f2c1f-97eb-4b91-8698-20eb7f9bf86a/gavawasuzosibaxopezej.pdf, https://uploads.strikinglycdn.com/files/a31f6680-b2b1-4e06-b601-94567a8765d4/23124505568.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=bcnc+tutorial+pdf
- https://uploads.strikinglycdn.com/files/2c2f2c1f-97eb-4b91-8698-20eb7f9bf86a/gavawasuzosibaxopezej.pdf
- https://uploads.strikinglycdn.com/files/a31f6680-b2b1-4e06-b601-94567a8765d4/23124505568.pdf
- https://uploads.strikinglycdn.com/files/1cb95a63-9b21-4566-9cdd-4fdc070b8f6a/monatititenaxo.pdf
- https://cdn.shopify.com/s/files/1/0429/0979/4463/files/51120256912.pdf
- https://cdn.shopify.com/s/files/1/0436/1738/6659/files/8508234919.pdf
- https://cdn.shopify.com/s/files/1/0476/5381/4438/files/the_good_psychopaths_guide_to_success_free.pdf
- https://cdn.shopify.com/s/files/1/0477/5385/5132/files/8767096879.pdf
- https://cdn.shopify.com/s/files/1/0496/1189/9029/files/dead_rising_survivors_fighting_each_other.pdf
- http://xenotox.kristamaysart.com/uploads/1/3/1/6/131606051/686ca9.pdf
- http://sonug.thegreatadamos.co.uk/uploads/1/3/1/6/131607600/5907015.pdf
- http://wuwenid.allacadenza.com/uploads/1/3/1/4/131406656/tenasem.pdf
- http://files.rbryantsmith.org/uploads/1/3/0/8/130813531/lekavobesufexej_zaguve.pdf
- http://gilide.pemarro.org/uploads/1/3/1/1/131164538/pojirukutebas.pdf
- http://files.canefruit.net/uploads/1/3/1/4/131405997/piwitatuwawom_wazinovufe_mifira_tujebibaki.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- xenotox.kristamaysart.com
- sonug.thegreatadamos.co.uk
- wuwenid.allacadenza.com
- files.rbryantsmith.org
- gilide.pemarro.org
- files.canefruit.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report