SUSPICIOUS — 257693857.pdf
SUSPICIOUS — 257693857.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
f41cf7226d3009198c7079fc6da3a38445ec9fc1851aad18d073a822e841b72c - SHA-1:
deebacd150506bc0cd45ea40557c7066e608e487 - MD5:
e8edce9f41b8e817d0de5e219c995e42 - ssdeep:
768:YgGzpDrCetnORiA7vJpGSfc+Oz1ERxpWIvLgo9GsKPr422V:1GF/76vlAirp9s2GsKz422V - TLSH:
T13F32AEF35897ED8CBA8697075DAB1591518AC34C7232A76058CCBB6CD4BC6FDBE00860 - Submitted as: 257693857.pdf
- File type: pdf · Size: 46044 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=bsg+guidelines+iron+deficiency, https://site-1039229.mozfiles.com/files/1039229/3670070046.pdf, https://site-1037182.mozfiles.com/files/1037182/20296284489.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=bsg+guidelines+iron+deficiency
- https://site-1039229.mozfiles.com/files/1039229/3670070046.pdf
- https://site-1037182.mozfiles.com/files/1037182/20296284489.pdf
- https://site-1043174.mozfiles.com/files/1043174/57736580320.pdf
- https://site-1042100.mozfiles.com/files/1042100/7006167183.pdf
- https://site-1043539.mozfiles.com/files/1043539/besevakarovogot.pdf
- https://uploads.strikinglycdn.com/files/ae3550a6-edc0-4f9f-8025-8d6fcd3539e0/13165008885.pdf
- https://uploads.strikinglycdn.com/files/9c14d433-9310-46da-8985-099c067b7784/sofagulegutoxulilaxemimes.pdf
- https://uploads.strikinglycdn.com/files/d7630f44-4a12-436b-a095-89ab56200eda/dusamisusuwe.pdf
- https://uploads.strikinglycdn.com/files/1e071860-51c2-4ec0-a20c-0ff56ed540e8/31325203224.pdf
- https://uploads.strikinglycdn.com/files/fecc0699-8489-4895-b3b6-bc1d61a67694/xopusozawijupoti.pdf
- https://cdn.shopify.com/s/files/1/0493/0886/0575/files/smart_strip_paint_remover_on_brick.pdf
- https://cdn.shopify.com/s/files/1/0481/5018/4085/files/kingdom_hearts_chain_of_memories_review.pdf
- https://cdn.shopify.com/s/files/1/0476/4876/8166/files/minecraft_white_bed_recipe.pdf
- https://cdn.shopify.com/s/files/1/0481/6578/1655/files/bomb_defusal_manual_2.pdf
- https://cdn.shopify.com/s/files/1/0482/6559/2987/files/15138388032.pdf
- http://files.empactathletics.com/uploads/1/3/0/7/130738712/85a4574561198.pdf
- http://xoxigop.riveroflifecambodia.org/uploads/1/3/1/4/131437046/supokukox.pdf
- http://files.theteethdr.com/uploads/1/3/1/6/131608017/sizibomupawudi.pdf
- http://files.dianegravel.com/uploads/1/3/0/7/130739924/kopep.pdf
- http://files.clubsandcommunity.com/uploads/1/3/1/0/131070356/jariwibolugixaw_mowoju_verodokurirevaj_ladogawora.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- site-1039229.mozfiles.com
- site-1037182.mozfiles.com
- site-1043174.mozfiles.com
- site-1042100.mozfiles.com
- site-1043539.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- files.empactathletics.com
- xoxigop.riveroflifecambodia.org
- files.theteethdr.com
- files.dianegravel.com
- files.clubsandcommunity.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report