SUSPICIOUS — 86665610334.pdf
SUSPICIOUS — 86665610334.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
cb6f902faf663634ca0a48f9ab0c1f49c0bdef53909b14dd3fedf73df5aadb72 - SHA-1:
3fd38d49fc1e387d9007e84f70983cc8e6239460 - MD5:
3481fad914cb8bf71349eae495de81d9 - ssdeep:
1536:jGF6JcT00yJ3Fh3dxuLA8/GUrjnGKhGbJDx:yF6O0vWrjGiGbn - TLSH:
T1AF34AEF31193EC8C7E9F5F439D9A10ADA18ACA846026D76018C9BB2DD43C6FD7E50612 - Submitted as: 86665610334.pdf
- File type: pdf · Size: 54877 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=kappa+sigma+bononia+docet+pdf, http://titomezuf.lizhumestudio.com/uploads/1/3/1/8/131856166/276519.pdf, http://files.mtmv.net/uploads/1/3/1/4/131437859/96335569.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=kappa+sigma+bononia+docet+pdf
- http://titomezuf.lizhumestudio.com/uploads/1/3/1/8/131856166/276519.pdf
- http://files.mtmv.net/uploads/1/3/1/4/131437859/96335569.pdf
- http://napaluje.sieglindemcgee.com/uploads/1/3/1/4/131407836/teteworazebinu.pdf
- http://files.hawkecreations.online/uploads/1/3/2/6/132682929/fukezusapuv_kudex.pdf
- http://files.crowlitmag.com/uploads/1/3/2/6/132696210/fbfceb.pdf
- http://files.alexvincenttextiles.com/uploads/1/3/1/3/131383247/janovatuz-gepobapef-xepewuripedek-xuvawelujola.pdf
- http://darirofo.wolfmatters.org/uploads/1/3/1/3/131379899/veberuganomeren.pdf
- http://files.osborneranch.com/uploads/1/3/0/9/130968960/rupetom.pdf
- http://fejolegi.gentlespiritdoula.org/uploads/1/3/0/7/130739353/xobex_vekukuv_zajen_tafaxexizoxepu.pdf
- http://files.grcrowfamily.com/uploads/1/3/1/0/131070190/3426f7e.pdf
- https://cdn.shopify.com/s/files/1/0430/0469/0581/files/varivefutuxef.pdf
- https://cdn.shopify.com/s/files/1/0429/0255/2735/files/writing_the_natural_way.pdf
- https://cdn.shopify.com/s/files/1/0463/0691/8557/files/38723884962.pdf
- https://cdn.shopify.com/s/files/1/0441/0202/5368/files/campton_semibold_font.pdf
- https://cdn.shopify.com/s/files/1/0463/0478/8637/files/rohs_2_compliance_certificate_template.pdf
- http://dupinodo.deborahshulmanmsw.com/uploads/1/3/1/8/131871825/guzenexajokej.pdf
- http://dovega.mrohagan.com/uploads/1/3/2/7/132740281/eea5141fdda53dc.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- titomezuf.lizhumestudio.com
- files.mtmv.net
- napaluje.sieglindemcgee.com
- files.hawkecreations.online
- files.crowlitmag.com
- files.alexvincenttextiles.com
- darirofo.wolfmatters.org
- files.osborneranch.com
- fejolegi.gentlespiritdoula.org
- files.grcrowfamily.com
- cdn.shopify.com
- dupinodo.deborahshulmanmsw.com
- dovega.mrohagan.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report