SUSPICIOUS — 72600407030.pdf
SUSPICIOUS — 72600407030.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e7f98fe9eaf99862c18d82a064c74be0541a0265af1e64c7497302c38b62fac1 - SHA-1:
917d2d06e71d650862435b5074b013fce9a4980a - MD5:
7920701a4a9e5d0485dfdf151d0471b4 - ssdeep:
1536:PGF2ewf4MYDOoV1Pzh0spqb3tOIWZ+lP5tt8:+F2ewQhDdjzh5pqtOJm0 - TLSH:
T12B349EF3259BDC8876C69B4358F720551587C75C32239BA015CDBB2CC5BC2BCAE109A0 - Submitted as: 72600407030.pdf
- File type: pdf · Size: 52438 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=biblia+pdf+download+free, http://files.rosepetalscafe.com/uploads/1/3/0/8/130813416/zetopemibelon.pdf, http://files.u-surge.net/uploads/1/3/0/7/130739740/3796923.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=biblia+pdf+download+free
- http://files.rosepetalscafe.com/uploads/1/3/0/8/130813416/zetopemibelon.pdf
- http://files.u-surge.net/uploads/1/3/0/7/130739740/3796923.pdf
- http://xonas.bizsign.shop/uploads/1/3/2/6/132681192/rogurerawimida_zasozutezipemex.pdf
- http://files.retreatinsider.net/uploads/1/3/1/3/131379803/mafafat.pdf
- http://jekazisik.thesharonstar.org/uploads/1/3/2/6/132681862/767a54.pdf
- http://xowuwu.jingyouecon.com/uploads/1/3/0/7/130740206/tujokuratedexu.pdf
- http://waledi.givshighcaliberbeagles.com/uploads/1/3/0/7/130740558/pudef.pdf
- http://files.nzgolfdoctor.com/uploads/1/3/0/8/130813582/ba16edd0648b.pdf
- http://files.emmabattenauthor.com/uploads/1/3/1/4/131483234/voziwuvabixelen.pdf
- http://files.shoehutmgk.com/uploads/1/3/1/4/131406036/5618453.pdf
- http://files.witneyhypnotherapy.co.uk/uploads/1/3/1/4/131408415/toputonijusok.pdf
- http://ritijawed.lovegrowbuild.com/uploads/1/3/0/8/130874118/8909125.pdf
- http://xijude.sfusoca.ca/uploads/1/3/1/6/131606968/3393074.pdf
- http://files.jkgeography.com/uploads/1/3/1/6/131636825/gojikuja_fenafumixaxeraw_dirupujafogele_likinirinid.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- files.rosepetalscafe.com
- files.u-surge.net
- xonas.bizsign.shop
- files.retreatinsider.net
- jekazisik.thesharonstar.org
- xowuwu.jingyouecon.com
- waledi.givshighcaliberbeagles.com
- files.nzgolfdoctor.com
- files.emmabattenauthor.com
- files.shoehutmgk.com
- files.witneyhypnotherapy.co.uk
- ritijawed.lovegrowbuild.com
- xijude.sfusoca.ca
- files.jkgeography.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report