SUSPICIOUS — 65835949649.pdf
SUSPICIOUS — 65835949649.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
d891a4006f73baa0ccfe5e2431ea048606ce6aea1b7b5f7b49ea28b41e71d60b - SHA-1:
8033f48629e346588f9ccc804b4f33c44e490d7e - MD5:
3edee41fe7dce33d38735cb1ae1588fd - ssdeep:
3072:FFbc8umpZqkI4KpA7cDG0PO9fItAQzDSSfcr:LWyc6+G39fItM - TLSH:
T1823BE0F700ABDD4C768BAB0BFCBA31455208C649A175A3A084CD3B7D89FC2BD2D54952 - Submitted as: 65835949649.pdf
- File type: pdf · Size: 105716 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=behaviourism+and+cognitivism+pdf, http://xaxasuso.alamedanavyleague.org/uploads/1/3/0/9/130969742/9686466.pdf, http://files.forgivenessfactor.org/uploads/1/3/1/3/131379860/medamanov.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=behaviourism+and+cognitivism+pdf
- http://xaxasuso.alamedanavyleague.org/uploads/1/3/0/9/130969742/9686466.pdf
- http://files.forgivenessfactor.org/uploads/1/3/1/3/131379860/medamanov.pdf
- http://neloxat.didactic-engineering.com/uploads/1/3/1/4/131406086/loboruba_woguwuji_kedotipatife_tewege.pdf
- http://vixulux.hotelinmontereyca.com/uploads/1/3/1/1/131164250/4004121.pdf
- http://files.kwbcdeaf.com/uploads/1/3/0/7/130739987/wowajuxebaza_zorepukakar_rejebunevedif.pdf
- https://uploads.strikinglycdn.com/files/faedc704-097a-4697-a1f3-29f3be70d0e4/22777574554.pdf
- https://uploads.strikinglycdn.com/files/06ccd292-ce38-44bb-926a-7f3b7bbb0f40/85859542173.pdf
- https://uploads.strikinglycdn.com/files/b98d0f43-b9be-47c6-a82c-e6cd436bfc58/fokuronowe.pdf
- https://uploads.strikinglycdn.com/files/762626f8-a79a-42ee-8b12-32778aa82167/70642292218.pdf
- https://uploads.strikinglycdn.com/files/51a4a6bf-8242-4c5c-ba96-a94029038a9d/womumupofob.pdf
- https://uploads.strikinglycdn.com/files/e6812bf2-1f4c-4679-8012-d98fbe617693/63377064094.pdf
- http://wajemexor.asiamitchelltabb.com/uploads/1/3/2/6/132695569/pozikulufexudet.pdf
- http://files.thewell-seasonedwoman.com/uploads/1/3/1/1/131163782/7405820defc07e2.pdf
- http://files.megcullar.com/uploads/1/3/2/8/132815961/favajuvidafoz.pdf
- http://xukaba.detail4less.com/uploads/1/3/1/4/131438741/b0234933065be.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- xaxasuso.alamedanavyleague.org
- files.forgivenessfactor.org
- neloxat.didactic-engineering.com
- vixulux.hotelinmontereyca.com
- files.kwbcdeaf.com
- uploads.strikinglycdn.com
- wajemexor.asiamitchelltabb.com
- files.thewell-seasonedwoman.com
- files.megcullar.com
- xukaba.detail4less.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report