SUSPICIOUS — timagosuwabeporat.pdf
SUSPICIOUS — timagosuwabeporat.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
d771396bbd9fd0a6b28181d8d1d60108c526087c7104913b6b47bcbd75caf694 - SHA-1:
fa60b5155603829c13dd0f90ab59b5fee503cc3e - MD5:
2b14516c495684a4bba08dec9014442b - ssdeep:
768:KgGzpDnJHQC9Nccf9kE2PHkW77BMebYNZNvIAyT8GLovW1BH4a:XGFrvfM5fqebU7IAyjMviH4a - TLSH:
T1F2308DF35087CCCC768AAF13BAAA008A6146C68D7062963425DC776CC5BC7FD9E14A70 - Submitted as: timagosuwabeporat.pdf
- File type: pdf · Size: 39272 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=html+to+pdf+react, https://cdn.shopify.com/s/files/1/0430/7160/2855/files/28318067739.pdf, https://cdn.shopify.com/s/files/1/0436/5529/9237/files/51713313113.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=html+to+pdf+react
- https://cdn.shopify.com/s/files/1/0430/7160/2855/files/28318067739.pdf
- https://cdn.shopify.com/s/files/1/0436/5529/9237/files/51713313113.pdf
- https://cdn.shopify.com/s/files/1/0432/0083/9841/files/text_plain_date_format_phpmyadmin.pdf
- http://files.valhallasforge.com/uploads/1/3/1/6/131606260/4821288.pdf
- http://bikuvipo.erikalancaster.com/uploads/1/3/1/3/131383329/49b9eab07c3c.pdf
- https://uploads.strikinglycdn.com/files/b1154712-ca5d-4736-ba8e-9f04a75f1266/8535497386.pdf
- https://uploads.strikinglycdn.com/files/0c9ba003-7861-4ec8-bbe3-e03f039237db/wisepaxexomuxolipusezoma.pdf
- https://uploads.strikinglycdn.com/files/126a5f80-dee3-4930-991e-3dade8f78872/24019143850.pdf
- https://site-1036661.mozfiles.com/files/1036661/sobuvodixagijipodulevumaj.pdf
- https://site-1037130.mozfiles.com/files/1037130/39140973809.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- files.valhallasforge.com
- bikuvipo.erikalancaster.com
- uploads.strikinglycdn.com
- site-1036661.mozfiles.com
- site-1037130.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report