SUSPICIOUS — 5644f9eb0f27e.pdf
SUSPICIOUS — 5644f9eb0f27e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
22a488613e1cd48699d7c33dc5fa60910699e41653499aa198ba77e33eb912e4 - SHA-1:
a7787d920e17f13306bbb273091d1615c4bf37fe - MD5:
1c378df2a9f267bcbb86f04e3b47bc7e - ssdeep:
768:vgGzpD/p17wP6HZ2aM/XCk5wWGjlVz80OcDrb4EO0+sJlcWuu3mb7NENmcxn6I:YGFjp8XjKWGZVzq0b4Ews0WuuiNEocxd - TLSH:
T1C632AEF34197EC4CBA8A9B139EFA116E518AD34D6135979044CC7B2DC47C2EEBE108A1 - Submitted as: 5644f9eb0f27e.pdf
- File type: pdf · Size: 47328 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=game%20dev%20story%20apk%20obb, https://uploads.strikinglycdn.com/files/a5fba4d0-1f9c-49eb-9500-b57cff76a117/28167370335.pdf, https://uploads.strikinglycdn.com/files/89c47c75-8570-4c57-b14d-dfb750e7dda1/62758207747.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=game%20dev%20story%20apk%20obb
- https://uploads.strikinglycdn.com/files/a5fba4d0-1f9c-49eb-9500-b57cff76a117/28167370335.pdf
- https://uploads.strikinglycdn.com/files/89c47c75-8570-4c57-b14d-dfb750e7dda1/62758207747.pdf
- https://uploads.strikinglycdn.com/files/be404336-3fcc-4b23-9cdc-144f6dfe6298/27410519036.pdf
- https://uploads.strikinglycdn.com/files/a1691aa9-7916-41e6-ac9c-785be4ac4dd3/keduvomuf.pdf
- https://uploads.strikinglycdn.com/files/14d5da2f-262e-4c8b-aedc-a0f291b26727/61785514051.pdf
- https://uploads.strikinglycdn.com/files/b44872fa-b871-467c-8c3a-898425dcd385/87652628258.pdf
- https://uploads.strikinglycdn.com/files/12ef2e62-7203-427f-8678-1e379aefc881/wumadusowupepe.pdf
- https://uploads.strikinglycdn.com/files/4191e0f3-07cd-4c61-9f26-febc6994184d/pivutori.pdf
- https://cdn.shopify.com/s/files/1/0432/8118/6972/files/japanese_learning_material.pdf
- https://cdn.shopify.com/s/files/1/0476/8982/6460/files/gamozujasisofav.pdf
- https://cdn.shopify.com/s/files/1/0430/9087/0423/files/vecinos_colombiana_capitulos_completos.pdf
- https://cdn.shopify.com/s/files/1/0480/3274/3583/files/84180238070.pdf
- https://cdn.shopify.com/s/files/1/0432/9691/5616/files/spanish_for_brown_sugar.pdf
- https://uploads.strikinglycdn.com/files/6c5bf430-84cb-4bae-a97e-31ce4e5c0e6e/46026526598.pdf
- https://uploads.strikinglycdn.com/files/741209f9-4a83-4076-a5f6-f487e01bdc25/pepigedeliriroxut.pdf
- https://uploads.strikinglycdn.com/files/a0eb24f1-767a-437a-8039-56b04c47db98/badamodoke.pdf
- https://uploads.strikinglycdn.com/files/6f823af6-e81d-438b-b23c-773e8f999262/wusijofowutikutewewat.pdf
- https://site-1042549.mozfiles.com/files/1042549/vetixonumoraliviji.pdf
- https://site-1042287.mozfiles.com/files/1042287/farapigisa.pdf
- https://site-1048576.mozfiles.com/files/1048576/71796121194.pdf
- https://xojisige.weebly.com/uploads/1/3/1/6/131637148/zofirafuvelotipuzi.pdf
- https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/7240363.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/porukofosu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1042549.mozfiles.com
- site-1042287.mozfiles.com
- site-1048576.mozfiles.com
- xojisige.weebly.com
- nudojafobedem.weebly.com
- dimaxafazeza.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report