SUSPICIOUS — 291a99.pdf
SUSPICIOUS — 291a99.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
2e5df6eed1571f30e685090beed76b9f5afa3afb6e389d0557fee89a1f60792e - SHA-1:
ad26b72d66d4173b8f1bd6effba08d4595524390 - MD5:
e7cec6934cd3a6d2f346798326adbeae - ssdeep:
768:agGzpDUeITzRM7bpnRV6uUnOhz4+Hf2NfY8fVpYB3tcvEWvZuOGyG4YG:HGFgeI/RWnquV2ayxYxtczvZRc4YG - TLSH:
T1F3358EF300A3DD8C7E8FBB43A9A7119A601AD78CB0269790448C776CC4B86FD6F11A51 - Submitted as: 291a99.pdf
- File type: pdf · Size: 58711 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=hipervitaminosis%20b12%20causas%20pdf, https://dopuxaponaxu.weebly.com/uploads/1/3/2/6/132695391/gusirapadotosixa.pdf, https://xogexemufak.weebly.com/uploads/1/3/1/4/131437987/javakagepomo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=hipervitaminosis%20b12%20causas%20pdf
- https://dopuxaponaxu.weebly.com/uploads/1/3/2/6/132695391/gusirapadotosixa.pdf
- https://xogexemufak.weebly.com/uploads/1/3/1/4/131437987/javakagepomo.pdf
- https://wipomozexabezi.weebly.com/uploads/1/3/0/7/130776841/tatode.pdf
- https://terarawuterojuz.weebly.com/uploads/1/3/0/7/130739827/f3c273a24b4e6.pdf
- https://cdn.shopify.com/s/files/1/0496/2251/5865/files/thomas_kuhn_structure_of_scientific_revolution.pdf
- https://cdn.shopify.com/s/files/1/0480/2091/4335/files/kobold_press_tome_of_beasts_5e.pdf
- https://cdn.shopify.com/s/files/1/0496/0292/0611/files/jomuvur.pdf
- https://uploads.strikinglycdn.com/files/a824d346-2f95-4559-a73f-1f0f3c52e3c7/logolaludofi.pdf
- https://uploads.strikinglycdn.com/files/419140b0-2751-4a9c-b869-8a1285eac636/tewirixaxorofegaj.pdf
- https://uploads.strikinglycdn.com/files/244905f2-d89f-4312-9faf-6216defa147d/gugivozadasuliwufatab.pdf
- https://uploads.strikinglycdn.com/files/356bcf61-ba74-455f-91c0-c3a80aa85dff/84061261952.pdf
- https://cdn.shopify.com/s/files/1/0485/3701/0331/files/xazezoxipapukoxizinimaven.pdf
- https://cdn.shopify.com/s/files/1/0485/0375/0811/files/48189328701.pdf
- https://cdn.shopify.com/s/files/1/0477/2010/4092/files/viking_oven_parts_manual.pdf
- https://uploads.strikinglycdn.com/files/3a69f7fe-648a-4df0-a720-0961489786ab/refupibefumosokilonuwal.pdf
- https://uploads.strikinglycdn.com/files/0e459c90-1c18-4c6c-a660-ea0dfb1427f2/pulifina.pdf
- https://uploads.strikinglycdn.com/files/a9f0f1e7-43d2-4543-9f8d-eade7e8fd5dc/vodago.pdf
- https://uploads.strikinglycdn.com/files/5d911cc9-ee3f-4c72-8734-e3c90fe0813f/37061916194.pdf
- https://uploads.strikinglycdn.com/files/ee289123-df5d-4da7-9f99-b12ff4bff461/all_mega_evolutions_pokemon_go.pdf
- https://uploads.strikinglycdn.com/files/1e722dae-c7cd-41fb-9377-d13840d5dbe4/northern_vermont_university_microsoft_word_download_os_x.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- dopuxaponaxu.weebly.com
- xogexemufak.weebly.com
- wipomozexabezi.weebly.com
- terarawuterojuz.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report