SUSPICIOUS — 83510173518.pdf
SUSPICIOUS — 83510173518.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
fe2b9bd226dc5e69426051ecd3f84afdbf6a44dbafaf0d0ad3c12612c1e0e2be - SHA-1:
ac0b5f24f8058bc09a492634cbdfa8b75b02548b - MD5:
498a21de3e9a805c29b9a0a3d0510e62 - ssdeep:
768:IgGzpDeqQuu2XRiRmIy3giJk1KAzmql5kAa3vRtQyo+y3KkBd:FGFiCIrTK8lq0F6kP - TLSH:
T1B9319EF310ABEC8C7A9AAF035AEB1A597149C38D617796A01488771CC47C6FCBF00965 - Submitted as: 83510173518.pdf
- File type: pdf · Size: 43186 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=grammar+practice+worksheets+pdf, https://uploads.strikinglycdn.com/files/41837999-714a-447e-8f8e-e3301395923d/70947156193.pdf, https://uploads.strikinglycdn.com/files/43e12aa6-575c-4d14-b6da-f61da6065c79/kotunivo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: additional-actions, uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=grammar+practice+worksheets+pdf
- https://uploads.strikinglycdn.com/files/41837999-714a-447e-8f8e-e3301395923d/70947156193.pdf
- https://uploads.strikinglycdn.com/files/43e12aa6-575c-4d14-b6da-f61da6065c79/kotunivo.pdf
- https://uploads.strikinglycdn.com/files/f131cf43-b0c4-46b2-96ff-0961da0963b7/36841487992.pdf
- https://cdn.shopify.com/s/files/1/0429/1756/0473/files/49423944845.pdf
- https://cdn.shopify.com/s/files/1/0430/4420/8797/files/55992465535.pdf
- https://cdn.shopify.com/s/files/1/0429/2860/3295/files/gonufovogapune.pdf
- https://cdn.shopify.com/s/files/1/0432/9829/1870/files/xizuwivuwugatutujefod.pdf
- https://cdn.shopify.com/s/files/1/0428/9835/8432/files/40369191557.pdf
- http://zurov.flowerdeb.com/uploads/1/3/1/8/131856166/didozepuj-bafabovorusiz.pdf
- http://files.annadowling.net/uploads/1/3/1/3/131380456/84288718730c0d.pdf
- http://sixelijis.tropicalswims.com/uploads/1/3/0/9/130969341/967881.pdf
- http://files.sarahclariusphotography.com/uploads/1/3/0/7/130740130/zowobaxug.pdf
- http://seren.driftset.net/uploads/1/3/0/9/130969360/vilevadujabag_xijaxukeb_rikuvoguluku_sasud.pdf
- http://files.travelingpillar.com/uploads/1/3/2/7/132740264/rasagi_tisexakexow_vinesap.pdf
- http://wilaf.borsodifinejewellery.com.au/uploads/1/3/0/8/130814411/62255.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- zurov.flowerdeb.com
- files.annadowling.net
- sixelijis.tropicalswims.com
- files.sarahclariusphotography.com
- seren.driftset.net
- files.travelingpillar.com
- wilaf.borsodifinejewellery.com.au
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report