SUSPICIOUS — 60585427187.pdf
SUSPICIOUS — 60585427187.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
ef7188c21032dab4a2810fb97eb6c25d59e04a63a6a0ac5f56e26f2e7a8b9d96 - SHA-1:
20d001b3a0260a69aaccab7e3d44b22e073e913b - MD5:
541a89cc517884d3564f29329fe4cf2e - ssdeep:
768:ygGzpDuZ5A78cckPL2S6826TESdvpnRWPO2XMpEbqiGYFqL+qJnxXDAip0NBH3X:vGFCDJchhn72cpWiwqL+qvmNBH3X - TLSH:
T16434AFF31193DC4C79CBEF036DBB2498D586E3486162A7A0448C7B2DD0BC2AD6F50A65 - Submitted as: 60585427187.pdf
- File type: pdf · Size: 55734 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=xbox+one+minecraft+crafting+guide, https://xogotosab.weebly.com/uploads/1/3/4/3/134327909/tuwonize.pdf, https://sevivuninuk.weebly.com/uploads/1/3/4/4/134459749/05197eff3744.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=xbox+one+minecraft+crafting+guide
- https://xogotosab.weebly.com/uploads/1/3/4/3/134327909/tuwonize.pdf
- https://sevivuninuk.weebly.com/uploads/1/3/4/4/134459749/05197eff3744.pdf
- https://digafixi.weebly.com/uploads/1/3/0/7/130776371/ac2d9.pdf
- https://cdn.shopify.com/s/files/1/0266/9704/0063/files/63300684098.pdf
- https://cdn.shopify.com/s/files/1/0497/9346/6517/files/90460253130.pdf
- https://cdn.shopify.com/s/files/1/0483/0976/4251/files/37009397138.pdf
- https://cdn.shopify.com/s/files/1/0484/7134/3266/files/download_dolby_access_for_android.pdf
- https://uploads.strikinglycdn.com/files/213cdabf-7085-449f-b9ec-11db25bcf871/xiparadasixawewibogusone.pdf
- https://uploads.strikinglycdn.com/files/0d235b2b-54f1-4cf0-a32d-efe34d963508/35311366790.pdf
- https://uploads.strikinglycdn.com/files/04c0c19c-b29c-4cbd-a5f7-419950677217/15743269876.pdf
- https://uploads.strikinglycdn.com/files/69fa3d17-6d4e-4641-8555-04d84f55b0cd/zulepawupaxamuwexusoriku.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/zakeme.pdf
- https://midunufi.weebly.com/uploads/1/3/4/3/134387712/bb516.pdf
- https://kurikezexiwu.weebly.com/uploads/1/3/0/7/130775092/4317364.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/ratot_muweliwamopoj.pdf
- https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/suwowu.pdf
- https://cdn-cms.f-static.net/uploads/4369183/normal_5f8b5c4d2360c.pdf
- https://cdn-cms.f-static.net/uploads/4410432/normal_5f93fbd8ef223.pdf
- https://cdn-cms.f-static.net/uploads/4412165/normal_5f934f5be3def.pdf
- https://cdn-cms.f-static.net/uploads/4393485/normal_5f92428f078e1.pdf
- https://cdn-cms.f-static.net/uploads/4383445/normal_5f8e669533f31.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- xogotosab.weebly.com
- sevivuninuk.weebly.com
- digafixi.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- dimaxafazeza.weebly.com
- midunufi.weebly.com
- kurikezexiwu.weebly.com
- guwomenod.weebly.com
- sesuwulot.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report