SUSPICIOUS — 70630070990.pdf
SUSPICIOUS — 70630070990.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
c10c5caf571877b5da0a9b5aa3e28e9669fc70c0cdfb50184b87f05a98a14f6c - SHA-1:
7a93c52df30c767194e8088c9fe3ce1e02aac83c - MD5:
13c3fe9f19eebddaa9755ff689eba99f - ssdeep:
768:1gGzpDI5g4fN/oIAcaBq4aE+5bW3yz0Xd9KpvIJAgsEFerF:mGFkN/oIAcD4aEGBu3QvIzswerF - TLSH:
T1D033CFF30467FCCC75D5AB476DB20426A299D7887137977054D8BA3C88BC2BD6E41811 - Submitted as: 70630070990.pdf
- File type: pdf · Size: 51048 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=blighted+ovum+management+pdf, http://tugubu.stellaheducationcenter.org/uploads/1/3/1/0/131070080/zoworutiraziji.pdf, http://fupumude.restorativejustice.com/uploads/1/3/0/9/130968911/rotadiviru.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=blighted+ovum+management+pdf
- http://tugubu.stellaheducationcenter.org/uploads/1/3/1/0/131070080/zoworutiraziji.pdf
- http://fupumude.restorativejustice.com/uploads/1/3/0/9/130968911/rotadiviru.pdf
- http://files.zsofia-opraszabo.com/uploads/1/3/0/7/130775053/sefofupuxonen_bizelobo_femoxoz_zeluvopevidomeg.pdf
- http://tojufobu.edgeofstyle.net/uploads/1/3/0/7/130739297/774c56aa545.pdf
- http://files.islandarks.org/uploads/1/3/1/4/131406749/xozojovebup_gixev.pdf
- http://ruvedo.dmaww.org/uploads/1/3/2/6/132681692/mefebugafodilaw.pdf
- http://fexajoki.gocaptiva.com/uploads/1/3/1/4/131437774/xilob-wiwesunar-ginevovudobawe-pigixuf.pdf
- http://xezeg.kivistocarwash.com/uploads/1/3/1/8/131857144/d84629b.pdf
- http://files.studio-macs.com/uploads/1/3/1/3/131398125/robegujul.pdf
- http://lakiv.learning-chemistry.com/uploads/1/3/1/3/131380755/fefalovemetudonorini.pdf
- http://files.donalcox.com/uploads/1/3/0/8/130814769/8047314.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- tugubu.stellaheducationcenter.org
- fupumude.restorativejustice.com
- files.zsofia-opraszabo.com
- tojufobu.edgeofstyle.net
- files.islandarks.org
- ruvedo.dmaww.org
- fexajoki.gocaptiva.com
- xezeg.kivistocarwash.com
- files.studio-macs.com
- lakiv.learning-chemistry.com
- files.donalcox.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report