SUSPICIOUS — 94556726425.pdf
SUSPICIOUS — 94556726425.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
fee67698c5bc7ad8592e5438ea41d3616e5643b534255b3cc29af695a265e54a - SHA-1:
7cca6f2bb168716d852176051ee0dbc86c5041ab - MD5:
0fa3881fe500b00177067ba563c47f69 - ssdeep:
768:6gGzpD+U3p1Uq/Q36feoLKJOSHohC+t2dWo2/d3yxShsBeeKtbCdFX7V5XKGzQYs:nGFqYaq/Xf3BIdgtbCz8YVq/ - TLSH:
T1E235D0F7419BFD8C6A8AA7179CDA20516146C3C9B1329B205C9CBB7DC8BC63D7D50A80 - Submitted as: 94556726425.pdf
- File type: pdf · Size: 60981 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=buccal+smear+examination+pdf, http://wefiti.pleasantridgepiranhas.com/uploads/1/3/1/6/131607203/b3b62ee9c636e.pdf, http://libapiw.worldwidedobermans.com/uploads/1/3/0/8/130814229/2128fc9.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=buccal+smear+examination+pdf
- http://wefiti.pleasantridgepiranhas.com/uploads/1/3/1/6/131607203/b3b62ee9c636e.pdf
- http://libapiw.worldwidedobermans.com/uploads/1/3/0/8/130814229/2128fc9.pdf
- http://files.mnrpcv.org/uploads/1/3/1/4/131406867/04dbd8067b8.pdf
- http://files.greatlakesdebtrelief.com/uploads/1/3/1/0/131071151/7910945.pdf
- http://files.beardsleebuffalo.com/uploads/1/3/0/7/130739750/c638f10.pdf
- https://site-1039227.mozfiles.com/files/1039227/kododizigu.pdf
- https://site-1037266.mozfiles.com/files/1037266/levipibozo.pdf
- https://site-1037069.mozfiles.com/files/1037069/11576268714.pdf
- https://site-1036988.mozfiles.com/files/1036988/lulekifuw.pdf
- https://cdn.shopify.com/s/files/1/0433/4531/3941/files/addendum_to_lease_template.pdf
- https://cdn.shopify.com/s/files/1/0434/5335/0055/files/betujuna.pdf
- https://cdn.shopify.com/s/files/1/0433/8758/4675/files/tiefling_subraces_dnd_5e.pdf
- https://cdn.shopify.com/s/files/1/0432/6152/6179/files/sift_heads_world_act_7_newgrounds.pdf
- https://cdn.shopify.com/s/files/1/0433/4849/2438/files/regedijutukozovususipi.pdf
- http://files.danswell.org/uploads/1/3/1/4/131437655/rowaguvukuwonifebol.pdf
- http://files.bartleytempleumc.org/uploads/1/3/0/7/130776075/kabuzunalelibalix.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- wefiti.pleasantridgepiranhas.com
- libapiw.worldwidedobermans.com
- files.mnrpcv.org
- files.greatlakesdebtrelief.com
- files.beardsleebuffalo.com
- site-1039227.mozfiles.com
- site-1037266.mozfiles.com
- site-1037069.mozfiles.com
- site-1036988.mozfiles.com
- cdn.shopify.com
- files.danswell.org
- files.bartleytempleumc.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report