SUSPICIOUS — tokep.pdf
SUSPICIOUS — tokep.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
c78b25312c5e161f0d7065b0221af4cf31adc98e691cd6f8c75f84c585bd7eb9 - SHA-1:
db20ffb84a0db77b1106ec0a1bd0a14ea3c988db - MD5:
166fed77290195bc088a1602e4656a08 - ssdeep:
1536:nGFPpEHlagcm6uez4Ocj8/q4QOdLIyJDD:GFPpE2m6uezvJqUEyV - TLSH:
T16036CFF31597FD8C7B865B43A9AB20552248DB8C2173AB7019957A7CC47C6BCBF009A0 - Submitted as: tokep.pdf
- File type: pdf · Size: 64377 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=hanuman%20chalisa%20in%20telugu%20pdf, https://cdn.shopify.com/s/files/1/0498/9331/0631/files/kasaxegobezov.pdf, https://cdn.shopify.com/s/files/1/0433/5144/1563/files/poxafidupasini.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=hanuman%20chalisa%20in%20telugu%20pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/kasaxegobezov.pdf
- https://cdn.shopify.com/s/files/1/0433/5144/1563/files/poxafidupasini.pdf
- https://cdn.shopify.com/s/files/1/0432/5841/3216/files/parsley_sage_rosemary_and_thyme_meaning.pdf
- https://cdn.shopify.com/s/files/1/0483/4594/0128/files/vutomepafukovuxiji.pdf
- https://cdn.shopify.com/s/files/1/0433/5150/7112/files/wowexup.pdf
- https://nelibijejukeli.weebly.com/uploads/1/3/1/4/131437261/537e91e3.pdf
- https://cdn-cms.f-static.net/uploads/4372955/normal_5f8a90c301aab.pdf
- https://cdn-cms.f-static.net/uploads/4366350/normal_5f87147f16513.pdf
- https://cdn-cms.f-static.net/uploads/4368740/normal_5f886bead7ee6.pdf
- https://cdn-cms.f-static.net/uploads/4367912/normal_5f8a326abbd0a.pdf
- https://dofazodasi.weebly.com/uploads/1/3/0/8/130873943/wodunik-nuzax-gatiradul.pdf
- https://pujatimosu.weebly.com/uploads/1/3/2/6/132681823/3062920.pdf
- https://cdn.shopify.com/s/files/1/0476/7727/6326/files/26607574822.pdf
- https://cdn.shopify.com/s/files/1/0484/2638/5576/files/ferosubomudoguloki.pdf
- https://cdn.shopify.com/s/files/1/0496/7297/8585/files/ordis_gun_gun_gun.pdf
- https://cdn.shopify.com/s/files/1/0434/4958/1724/files/ec_201_msu_fundamental_problem_sets.pdf
- https://cdn.shopify.com/s/files/1/0440/7777/7061/files/factorization_of_quadratic_polynomials_worksheet.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- nelibijejukeli.weebly.com
- cdn-cms.f-static.net
- dofazodasi.weebly.com
- pujatimosu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report