SUSPICIOUS — 1420159.pdf
SUSPICIOUS — 1420159.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
19c9d105f5e330efc863ac238e11b9d08dba41e7af1e8e459c5f7d1052cbc100 - SHA-1:
de909fe8c9259f54e61581263a96340cbfaa6f30 - MD5:
61d0d66f5481417f6c4a0a2b6e57457a - ssdeep:
768:NmgGzpDZdBke/y/2AlQ92p05e9QRzOPSaeIct+It0CqWdLIsT1+JSgWn21sqUw55:lGF90/2AlQxo9QLaereAgWpqUwlD/SE - TLSH:
T16C34CFF35697ED8C7552BB07AEF114A82446D78C2036A75098C8BB6CC0BC6FC6F54A21 - Submitted as: 1420159.pdf
- File type: pdf · Size: 54469 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=principles%20of%20marketing%2016th%20edition%20pdf%20free%20download, https://patelevenimo.weebly.com/uploads/1/3/1/4/131437444/xuzexuwaximisifej.pdf, https://uploads.strikinglycdn.com/files/fe81ce94-3b27-4fdb-8392-5e45717f1988/65957808564.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=principles%20of%20marketing%2016th%20edition%20pdf%20free%20download
- https://patelevenimo.weebly.com/uploads/1/3/1/4/131437444/xuzexuwaximisifej.pdf
- https://uploads.strikinglycdn.com/files/fe81ce94-3b27-4fdb-8392-5e45717f1988/65957808564.pdf
- https://cdn-cms.f-static.net/uploads/4367000/normal_5f872ff2dbff4.pdf
- https://uploads.strikinglycdn.com/files/b51a36f5-ced5-455a-b96b-3ed1a506779a/83349931172.pdf
- https://garagagu.weebly.com/uploads/1/3/4/3/134364865/7212277.pdf
- https://cdn-cms.f-static.net/uploads/4368951/normal_5f94238c10dd3.pdf
- https://cdn-cms.f-static.net/uploads/4418383/normal_5f99472d7b404.pdf
- https://cdn-cms.f-static.net/uploads/4369327/normal_5f88caadc294e.pdf
- https://cdn-cms.f-static.net/uploads/4374976/normal_5f8b347570970.pdf
- https://cdn-cms.f-static.net/uploads/4423752/normal_5f99688dd9407.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- patelevenimo.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- garagagu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report