SUSPICIOUS — 46218246755.pdf
SUSPICIOUS — 46218246755.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
f565eda82a0e475fd71947a917b44fe9d33636e3a115a8f745f6e4ee841ebf72 - SHA-1:
04ceb1d9bca87080ada2431dee8df378214753cd - MD5:
10598db6796d8778ad21531158f0d8bc - ssdeep:
768:sgGzpDF8uNswqkKqs1koiE3pv9yGzFrbtHvq//M0AWgl:pGFh8jwqkhih9yctNsBgl - TLSH:
T169319EF320A7ED8C7A8A6B479D9A111CB10AC7886137AB704598777CC4BC6FD6E414B0 - Submitted as: 46218246755.pdf
- File type: pdf · Size: 43214 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=manual+de+heladera+electrolux+dxw51, https://site-1036779.mozfiles.com/files/1036779/11411270477.pdf, https://site-1048487.mozfiles.com/files/1048487/dujotuzuxekuxedesetire.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=manual+de+heladera+electrolux+dxw51
- https://site-1036779.mozfiles.com/files/1036779/11411270477.pdf
- https://site-1048487.mozfiles.com/files/1048487/dujotuzuxekuxedesetire.pdf
- https://site-1040145.mozfiles.com/files/1040145/85611475947.pdf
- https://site-1037111.mozfiles.com/files/1037111/vivekisipifiwadem.pdf
- https://site-1036676.mozfiles.com/files/1036676/90273638559.pdf
- http://nipunu.insideemilyshead.com/uploads/1/3/1/0/131070197/8474853.pdf
- http://files.bengoughbulletin.com/uploads/1/3/0/7/130738765/4051362.pdf
- http://files.statsworldcollectibles.com/uploads/1/3/1/4/131453917/gosukenuvov_xorot.pdf
- http://zelota.zgatl.org/uploads/1/3/1/3/131379182/2f9df86be12e.pdf
- http://ruberota.eosmithfoundation.org/uploads/1/3/2/6/132682156/63fa2845ba6fa4.pdf
- http://nipebenif.homeopathycare.org/uploads/1/3/1/4/131437361/rubijemokonebajewiwa.pdf
- http://tewov.aatp-mysterygames.com/uploads/1/3/0/8/130814347/27e981b01ec15.pdf
- http://jikes.baase.co.uk/uploads/1/3/1/0/131069934/6193602.pdf
- http://kekutaba.spotlighteditorial.com/uploads/1/3/0/7/130775840/68a76a5f30606.pdf
- http://files.londonsustainableschools.org/uploads/1/3/1/4/131437513/tunakapa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1036779.mozfiles.com
- site-1048487.mozfiles.com
- site-1040145.mozfiles.com
- site-1037111.mozfiles.com
- site-1036676.mozfiles.com
- nipunu.insideemilyshead.com
- files.bengoughbulletin.com
- files.statsworldcollectibles.com
- zelota.zgatl.org
- ruberota.eosmithfoundation.org
- nipebenif.homeopathycare.org
- tewov.aatp-mysterygames.com
- jikes.baase.co.uk
- kekutaba.spotlighteditorial.com
- files.londonsustainableschools.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report