SUSPICIOUS — 25693309391f5.pdf
SUSPICIOUS — 25693309391f5.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
091ed267417ef8e3e3c9751a10c8c0058ad7c66c60c1601e0f690a5ebd489432 - SHA-1:
984a5355b9b134058cc38f796ea1a97a606c2547 - MD5:
4d6c8368ecebb4ec1b6d60d0baec7b88 - ssdeep:
768:cgGzpD3phy6JwmGeH8s0LFleuEN8ZiVA9T+XhA5feSdIpKapmmhqLnb:5GFrphbJLo9T+x+dIp9hqLnb - TLSH:
T17A329EF750ABDD4C7AC66B13ADE604666988D7C86127AB7019C8FB2CC43C6BD7E00950 - Submitted as: 25693309391f5.pdf
- File type: pdf · Size: 44474 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=toyota%205a%20engine%20wiring%20diagram, https://uploads.strikinglycdn.com/files/97459d24-ab7f-4955-bc33-7242dd12db63/67352551978.pdf, https://uploads.strikinglycdn.com/files/4da0e73b-25da-4390-bd97-83afa1571f02/pufaranas.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=toyota%205a%20engine%20wiring%20diagram
- https://uploads.strikinglycdn.com/files/97459d24-ab7f-4955-bc33-7242dd12db63/67352551978.pdf
- https://uploads.strikinglycdn.com/files/4da0e73b-25da-4390-bd97-83afa1571f02/pufaranas.pdf
- https://uploads.strikinglycdn.com/files/01f9afba-46a9-4f26-9d39-9e3fcaad586b/9507321318.pdf
- https://uploads.strikinglycdn.com/files/d9eecdb4-b6aa-4bac-9095-cca624712f42/18311886717.pdf
- https://uploads.strikinglycdn.com/files/e42c2be9-d82d-4851-9396-9af3fcc644a4/veviliral.pdf
- https://cdn-cms.f-static.net/uploads/4366662/normal_5f87752cb6865.pdf
- https://cdn-cms.f-static.net/uploads/4367656/normal_5f874c9308868.pdf
- https://cdn-cms.f-static.net/uploads/4365634/normal_5f8766dc444fb.pdf
- https://cdn-cms.f-static.net/uploads/4365662/normal_5f872b2f8218b.pdf
- https://cdn-cms.f-static.net/uploads/4367312/normal_5f877fdc51c51.pdf
- https://cdn-cms.f-static.net/uploads/4365589/normal_5f8754fa6ba32.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f877d21a0e40.pdf
- https://cdn-cms.f-static.net/uploads/4365560/normal_5f876d2ba6321.pdf
- https://cdn-cms.f-static.net/uploads/4365626/normal_5f871819a6906.pdf
- https://cdn.shopify.com/s/files/1/0438/6373/6485/files/3366564474.pdf
- https://cdn.shopify.com/s/files/1/0429/3961/3347/files/dual_agar_online.pdf
- https://cdn.shopify.com/s/files/1/0497/0056/9253/files/call_of_duty_mw3_cheats_xbox360.pdf
- https://cdn.shopify.com/s/files/1/0495/9846/4152/files/spirit_dancer_guide_dragon_nest_mobile.pdf
- https://site-1043975.mozfiles.com/files/1043975/mopojuwavo.pdf
- https://site-1037848.mozfiles.com/files/1037848/33339534485.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1043975.mozfiles.com
- site-1037848.mozfiles.com
- w.au
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report