SUSPICIOUS — 39455230808.pdf
SUSPICIOUS — 39455230808.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
bfef9eac4dc185dfabc2b11e8b489fc1391a8d1d6477f36847d9636ab1915cf1 - SHA-1:
07011d9e3131d682e268a803e278e827021e7ad6 - MD5:
d54569c248108e0d3ba09e7b6aa7f0d7 - ssdeep:
768:QgGzpDrHUQEifbQ0mfljytOmB/+iSM9n7mYwoncVEf79DBowG7VcG76sz:9GFXElE/sEn7mYwonBRDBowG5cGfz - TLSH:
T1C8328DF310A7EE8C3A8A6B839EA7019D618AD74C713786601598777DC47C6ED7F00921 - Submitted as: 39455230808.pdf
- File type: pdf · Size: 45458 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=aceptaciones+bancarias+pdf, http://files.drandrewhoward.com/uploads/1/3/2/6/132681362/4412484.pdf, http://files.laimun.org/uploads/1/3/0/7/130775346/letunolofisajulaf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=aceptaciones+bancarias+pdf
- http://files.drandrewhoward.com/uploads/1/3/2/6/132681362/4412484.pdf
- http://files.laimun.org/uploads/1/3/0/7/130775346/letunolofisajulaf.pdf
- http://xamejomun.ohmsweethomeorganizing.com/uploads/1/3/1/6/131637309/biwoboxanedafufo.pdf
- http://files.christiantedeschi.net/uploads/1/3/0/9/130969238/de36831f903f3.pdf
- http://files.ouidancema.com/uploads/1/3/0/8/130874305/59d6a4eb0f4fd9.pdf
- https://cdn.shopify.com/s/files/1/0428/9075/6252/files/97195762720.pdf
- https://cdn.shopify.com/s/files/1/0482/9478/9275/files/thai_ridgeback_dog_breed_info.pdf
- https://cdn.shopify.com/s/files/1/0436/9874/9608/files/14156229299.pdf
- https://cdn.shopify.com/s/files/1/0481/0670/0963/files/9990253260.pdf
- https://site-1038572.mozfiles.com/files/1038572/xirilanonu.pdf
- https://site-1037869.mozfiles.com/files/1037869/18237230872.pdf
- https://site-1036923.mozfiles.com/files/1036923/vekamuwukerezewi.pdf
- https://uploads.strikinglycdn.com/files/2ce41300-edc0-43af-b331-24e445137efa/guwefonosukorasajugego.pdf
- https://uploads.strikinglycdn.com/files/d0d15d1b-e25b-4399-bdf6-51a751e7e617/xurizokuwosimivokaguma.pdf
- https://uploads.strikinglycdn.com/files/2aa39d3c-6658-4990-b5d5-11ba8cac379d/37160196318.pdf
- https://uploads.strikinglycdn.com/files/0e2ed30a-15ca-4f1e-8cb4-fef0c51a0157/73425545991.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- files.drandrewhoward.com
- files.laimun.org
- xamejomun.ohmsweethomeorganizing.com
- files.christiantedeschi.net
- files.ouidancema.com
- cdn.shopify.com
- site-1038572.mozfiles.com
- site-1037869.mozfiles.com
- site-1036923.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report