SUSPICIOUS — my_tax_bill_naugatuck.pdf
SUSPICIOUS — my_tax_bill_naugatuck.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
d67cc5422aeac3849c74dd9e3da0d6586cbe26d93d7a7543df4f9233e0d546b1 - SHA-1:
9fae4f044f1d9ab48e16dacf01f6ffaebe4fe920 - MD5:
bd591414835a7bab9e465163cb384ec5 - ssdeep:
768:AgGzpD7pVL+XGvzYJQgZ2pyfGwC1r1TmaznaXQ1G8EyfjQKu9KPvbPmL5/h:NGFvpVH91TO8EyfjQKqKPvbOZh - TLSH:
T1EA329DF35497ED4C6D86AB53ADAA192A144AC3496277E760058C332CD9BCABD7F00C70 - Submitted as: my_tax_bill_naugatuck.pdf
- File type: pdf · Size: 43515 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=my+tax+bill+naugatuck, https://cdn.shopify.com/s/files/1/0429/2454/0071/files/laars_lx_pool_heater_manual.pdf, https://cdn.shopify.com/s/files/1/0438/7006/0704/files/32323878732.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=my+tax+bill+naugatuck
- https://cdn.shopify.com/s/files/1/0429/2454/0071/files/laars_lx_pool_heater_manual.pdf
- https://cdn.shopify.com/s/files/1/0438/7006/0704/files/32323878732.pdf
- https://cdn.shopify.com/s/files/1/0435/5027/7791/files/heart_foundation_chronic_heart_failure_guidelines.pdf
- https://cdn.shopify.com/s/files/1/0485/0185/0273/files/90663138016.pdf
- https://uploads.strikinglycdn.com/files/f4d6821d-92fe-4777-a364-a936ff642de0/30185971026.pdf
- https://uploads.strikinglycdn.com/files/8e69c546-488b-4646-ab4e-aa8cb1fd1a2b/75583180439.pdf
- https://uploads.strikinglycdn.com/files/2e17c447-6279-4b36-9ad3-78c0ba7fa275/93545122531.pdf
- https://uploads.strikinglycdn.com/files/3bc7f5e3-c13c-4b40-9ea5-b1071f85f363/79151236279.pdf
- https://uploads.strikinglycdn.com/files/31c0a88f-aaff-494b-9e4b-a822392147db/74473783011.pdf
- https://uploads.strikinglycdn.com/files/2f1ee2ca-b413-4875-88b0-427510ec7b2f/pobavesi.pdf
- https://uploads.strikinglycdn.com/files/1c3968e2-e3a0-46d7-b809-c9efcc180c89/xoserate.pdf
- https://uploads.strikinglycdn.com/files/1d366884-2812-4b97-919b-e15d98379c27/votabusigexagena.pdf
- https://uploads.strikinglycdn.com/files/94842aab-5623-4519-879f-5af9a409652b/2906692696.pdf
- https://uploads.strikinglycdn.com/files/ad636da8-ceee-4829-b8b6-7e5d2f34693d/6789089648.pdf
- https://uploads.strikinglycdn.com/files/401be851-5939-4d33-b958-03d4f2fc0698/51151471825.pdf
- https://cdn.shopify.com/s/files/1/0437/9928/1821/files/give_me_liberty_volume_2_free.pdf
- https://cdn.shopify.com/s/files/1/0462/9918/5312/files/mefolunozi.pdf
- https://cdn.shopify.com/s/files/1/0480/2383/0687/files/chapter_14_biology_study_guide_answers.pdf
- https://cdn.shopify.com/s/files/1/0486/7483/2534/files/spanish_writer_garcia_crossword.pdf
- https://cdn-cms.f-static.net/uploads/4366964/normal_5f8736df1f900.pdf
- https://cdn-cms.f-static.net/uploads/4368504/normal_5f88fe040fe0f.pdf
- https://cdn-cms.f-static.net/uploads/4367624/normal_5f87d9a70f4cc.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report