SUSPICIOUS — 98278850969.pdf
SUSPICIOUS — 98278850969.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
d9e79de3fb509ea7cebcb1529699f4e0181da6d8229cb711980c443abead7ca4 - SHA-1:
c91905965b256197f928ed6b010bc5730f01cdef - MD5:
90ec7f2e8b6e7949cf792520c67ca104 - ssdeep:
1536:2GFGKFGsoGLlK+XhYqWi1Ub7asDo4rY2+6s:PFG4Sb+XhYq5sDosY2i - TLSH:
T10E35CFF390A7EC8C7A8AD3836DA728491455D3C96236AB3045DD6B5CC4BC3BC7E50A60 - Submitted as: 98278850969.pdf
- File type: pdf · Size: 58972 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=casio+lk+110+release+date, http://juzur.sparklecityimprov.com/uploads/1/3/1/4/131453574/puwonabetetebe_lawagise.pdf, http://files.2020parkvision.org/uploads/1/3/2/6/132681664/8296320.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=casio+lk+110+release+date
- http://juzur.sparklecityimprov.com/uploads/1/3/1/4/131453574/puwonabetetebe_lawagise.pdf
- http://files.2020parkvision.org/uploads/1/3/2/6/132681664/8296320.pdf
- http://files.tooldesignsolutions.com/uploads/1/3/1/4/131437091/f9c7cd54.pdf
- http://files.easternsloperanch.com/uploads/1/3/2/6/132681404/3588728.pdf
- http://files.napashuttle.net/uploads/1/3/1/3/131381142/norulifafebok_wavaderuxu_geperunamunege.pdf
- https://cdn.shopify.com/s/files/1/0434/3929/2582/files/80611888425.pdf
- https://cdn.shopify.com/s/files/1/0429/8801/1673/files/fanelepetodogijanepuvep.pdf
- https://cdn.shopify.com/s/files/1/0484/3228/3805/files/74589261959.pdf
- https://cdn.shopify.com/s/files/1/0433/8656/8860/files/28118963490.pdf
- https://site-1036692.mozfiles.com/files/1036692/pijakavekasi.pdf
- https://site-1042988.mozfiles.com/files/1042988/65281603210.pdf
- https://site-1038890.mozfiles.com/files/1038890/23574533478.pdf
- https://cdn.shopify.com/s/files/1/0434/4882/8065/files/gw2_mastery_points_guide.pdf
- https://cdn.shopify.com/s/files/1/0432/7587/8564/files/ch_18_ap_bio_reading_guide_answers.pdf
- https://cdn.shopify.com/s/files/1/0482/9691/9204/files/pesokaworobunosi.pdf
- https://cdn.shopify.com/s/files/1/0481/4906/9991/files/58980844687.pdf
- https://cdn.shopify.com/s/files/1/0437/6310/5953/files/what_does_ftp_stand_for_blm.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- juzur.sparklecityimprov.com
- files.2020parkvision.org
- files.tooldesignsolutions.com
- files.easternsloperanch.com
- files.napashuttle.net
- cdn.shopify.com
- site-1036692.mozfiles.com
- site-1042988.mozfiles.com
- site-1038890.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report