SUSPICIOUS — 223505.pdf
SUSPICIOUS — 223505.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
1909ae62a94e13b9db7cafd0eaebbaaacca8fb4ab3c99a3138187d82a5a20a6f - SHA-1:
0e915697b40c97737a07d58141125086dc9ee49a - MD5:
97accddd179bfd564eca7642db5fd957 - ssdeep:
768:ukgGzpDKp8lMcRrOB1J577dnzq2AcMDJTr7B6KosjIiCq8ij05Ut1fsMIFsbS9G:uRGFmpzryU5siqNjHj/Ii+G - TLSH:
T19A349DF350A7ED4D7A8E6B4399AB115D618EC3CD6123979048882B2DD03CAFE3F10665 - Submitted as: 223505.pdf
- File type: pdf · Size: 53045 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=fallout%204%20workshop%20console%20commands, https://site-1038988.mozfiles.com/files/1038988/simelitugezenukogabomote.pdf, https://site-1039308.mozfiles.com/files/1039308/salafesavuronumafalalok.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=fallout%204%20workshop%20console%20commands
- https://site-1038988.mozfiles.com/files/1038988/simelitugezenukogabomote.pdf
- https://site-1039308.mozfiles.com/files/1039308/salafesavuronumafalalok.pdf
- https://site-1048208.mozfiles.com/files/1048208/sebujusumezebikafivalaf.pdf
- https://site-1041946.mozfiles.com/files/1041946/gasadaleduludok.pdf
- https://cdn.shopify.com/s/files/1/0428/8331/7926/files/5701737342.pdf
- https://cdn.shopify.com/s/files/1/0479/4384/3996/files/asmfish_engine_author.pdf
- https://cdn.shopify.com/s/files/1/0485/7934/6592/files/38997552188.pdf
- https://cdn.shopify.com/s/files/1/0500/3565/4816/files/tivedev.pdf
- https://cdn.shopify.com/s/files/1/0428/5962/6655/files/list_of_amino_acids.pdf
- https://cdn.shopify.com/s/files/1/0496/0242/9092/files/how_many_bits_are_in_an_ipv4_address_chapter_7.pdf
- https://cdn.shopify.com/s/files/1/0485/0601/1803/files/tramex_moisture_meter_rental.pdf
- https://cdn.shopify.com/s/files/1/0482/3279/2216/files/dronium_one_manual.pdf
- https://cdn.shopify.com/s/files/1/0494/6621/2519/files/bic_acoustech_pl-200_ii_vs_klipsch_r-12sw.pdf
- https://cdn.shopify.com/s/files/1/0430/6753/9605/files/dillon_rl550b_manual.pdf
- https://site-1038503.mozfiles.com/files/1038503/86506982614.pdf
- https://site-1042185.mozfiles.com/files/1042185/kopafenijuvigevurive.pdf
- https://uploads.strikinglycdn.com/files/113ea138-eb6a-4408-9ab3-842c8d61dc2b/7111013557.pdf
- https://uploads.strikinglycdn.com/files/e9894f5a-af7a-4679-bcdb-62918e13c4ad/pivov.pdf
- https://uploads.strikinglycdn.com/files/f81914f4-ff7e-463b-b74f-e91e97614473/36930904409.pdf
- https://uploads.strikinglycdn.com/files/eed9d531-a603-41b5-9d0a-a6b4de5b2bfb/satupetiwujuwal.pdf
- https://uploads.strikinglycdn.com/files/768a8b6c-fa79-42db-a840-dddc9bf8bc23/2945146057.pdf
- https://cdn-cms.f-static.net/uploads/4366628/normal_5f872eb941824.pdf
- https://cdn-cms.f-static.net/uploads/4366032/normal_5f878878c5318.pdf
- https://cdn-cms.f-static.net/uploads/4367286/normal_5f87d3bbf0558.pdf
Embedded domains
- gettraff.ru
- site-1038988.mozfiles.com
- site-1039308.mozfiles.com
- site-1048208.mozfiles.com
- site-1041946.mozfiles.com
- cdn.shopify.com
- site-1038503.mozfiles.com
- site-1042185.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report