SUSPICIOUS — 88345605160.pdf
SUSPICIOUS — 88345605160.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
1469c75dc707b761ef2c305814c48756134fc5e1c76a1ed303e7b93232a59e32 - SHA-1:
1b5f2a57dffaf22fe66e2e7f2f6046e68ed0f042 - MD5:
84200181ed9c60e1bbcda244f3040083 - ssdeep:
1536:mGFJ3I4PgyZBQtCSDz3iTUu5O3JI0oAqi3Pz:/FJ3IvyZoCS3385O3noAq2 - TLSH:
T1A634BFF791ABDD5C3587AF03AEE618584489D6083162A7B004DC3B7CC5BC6BC7E90A51 - Submitted as: 88345605160.pdf
- File type: pdf · Size: 54832 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=bugs+bunny+road+runner+movie+youtube, https://uploads.strikinglycdn.com/files/9227269c-7ce1-4397-88c5-bc7405ce2d30/benevefubalobilexe.pdf, https://uploads.strikinglycdn.com/files/12086c03-c187-4471-99bb-aeab844cbfbf/panedafebekivatazewejized.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=bugs+bunny+road+runner+movie+youtube
- https://uploads.strikinglycdn.com/files/9227269c-7ce1-4397-88c5-bc7405ce2d30/benevefubalobilexe.pdf
- https://uploads.strikinglycdn.com/files/12086c03-c187-4471-99bb-aeab844cbfbf/panedafebekivatazewejized.pdf
- https://uploads.strikinglycdn.com/files/e1f03c4c-7b04-4979-bf6d-bbec227f2dbc/58739449791.pdf
- https://uploads.strikinglycdn.com/files/014ae937-a3c6-4f22-b473-6bf3c1db88d3/wodapolafez.pdf
- https://uploads.strikinglycdn.com/files/475784d2-3615-4051-9a95-ec444832d3ab/97630833502.pdf
- https://cdn.shopify.com/s/files/1/0433/4659/1903/files/lobuf.pdf
- https://cdn.shopify.com/s/files/1/0431/6600/7445/files/piseduxusiseboxika.pdf
- https://cdn.shopify.com/s/files/1/0432/1568/3744/files/toward_a_critical_race_theory_of_education_apa_citation.pdf
- https://cdn.shopify.com/s/files/1/0501/5925/5717/files/gesuxefirabejivafiv.pdf
- https://cdn.shopify.com/s/files/1/0431/9703/8756/files/milky_way_chocolate_bar.pdf
- https://cdn.shopify.com/s/files/1/0479/4738/2940/files/sonic_after_the_sequel_dx_download_zip.pdf
- https://uploads.strikinglycdn.com/files/a4ed777f-e08f-43ef-8a8b-cccc3186e0a8/fefarimipiponadole.pdf
- https://uploads.strikinglycdn.com/files/dc3d0355-7d54-4d06-af37-f66185d4b08b/54268343073.pdf
- https://uploads.strikinglycdn.com/files/8319bb76-e945-4e3a-9585-44ac8b20bdb6/83372675675.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report