SUSPICIOUS — 65163536662.pdf
SUSPICIOUS — 65163536662.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
c786ed6bf2a55e86eee124084a6590d02f1553db7ebcf39c09e003538de2f15a - SHA-1:
dd584db1b3887aa828d3f3d8d2061a459ea3b23e - MD5:
6db3b15151934cb154e5ddcc6ca40c58 - ssdeep:
768:1gGzpDCJ6iDwLGM7bUuV7VeK820kSKqSEMay52mZU8M4N+UoNZhNKc:mGFOJ6wMn7VeD20kSKqSEMcmH5oHhNKc - TLSH:
T1FE33CEF30197EC88AF8797479EA604556089C388612793A425DD763EC4FCAFE7E01C61 - Submitted as: 65163536662.pdf
- File type: pdf · Size: 48475 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=hempire+free+diamonds, http://sovem.emateria.com/uploads/1/3/0/7/130776255/5678706.pdf, http://files.slicediaries.com/uploads/1/3/1/6/131606260/ritarijivomomur.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=hempire+free+diamonds
- http://sovem.emateria.com/uploads/1/3/0/7/130776255/5678706.pdf
- http://files.slicediaries.com/uploads/1/3/1/6/131606260/ritarijivomomur.pdf
- http://files.creativeedgestudio.co.nz/uploads/1/3/1/4/131453645/folonobasitalowubus.pdf
- http://kubaw.justkeephoping.com/uploads/1/3/2/6/132695550/jolezugaxope_mewukatiwiko_gokudak.pdf
- https://uploads.strikinglycdn.com/files/09630f87-ad13-4529-abc9-a3807bd34d02/99790163474.pdf
- https://uploads.strikinglycdn.com/files/b5324888-3fbc-4524-a532-f9cb5be7b69f/68109864235.pdf
- https://uploads.strikinglycdn.com/files/caca6fb2-e3b3-4029-b208-6d10de26265d/39942674636.pdf
- https://uploads.strikinglycdn.com/files/aa660577-7e93-44c1-9ea0-2536c7d53832/69896450572.pdf
- https://uploads.strikinglycdn.com/files/6a779567-486d-4f1d-a983-1aa4b4cca949/ruponopotofu.pdf
- https://uploads.strikinglycdn.com/files/33ee50dc-4a4e-4165-a327-49293769cfa1/xalukajixunejoj.pdf
- https://uploads.strikinglycdn.com/files/33264058-b993-4753-913f-4f0be8a42e70/telakolefosu.pdf
- https://uploads.strikinglycdn.com/files/ecd1fb41-821a-4c53-a3e0-40c3710b5e38/13902780228.pdf
- https://uploads.strikinglycdn.com/files/1a6a1cc6-c866-463b-a794-ed3b2288160c/wisetofune.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- sovem.emateria.com
- files.slicediaries.com
- kubaw.justkeephoping.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
- files.creativeedgestudio.co.nz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report