SUSPICIOUS — a34629d97c.pdf
SUSPICIOUS — a34629d97c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
38e7612cadfdb4f0695173f16c7e5adff38dd4c666cc6f8dfb6423d1196b4935 - SHA-1:
15ec55bc6c12f30eac151546395e00b359026d39 - MD5:
ae38b96e6e2f119fb28359e1abbb9239 - ssdeep:
768:XgGzpDNpxmcvo3CF2YwB/uyXWGdHSCtOO1UIZ0tRUmswwcHvs/pQr0SGQcU:wGFZpxuAQnStRUmsXcHk+ISGzU - TLSH:
T1BC318CF350A7ED8D7A86AB03ADA61155658AC78C2233E7A004CC7A3CD4BC6FD6F40851 - Submitted as: a34629d97c.pdf
- File type: pdf · Size: 40270 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=subway%20surfers%20tokyo%202018, https://cdn-cms.f-static.net/uploads/4366399/normal_5f87802fa79f7.pdf, https://cdn-cms.f-static.net/uploads/4365619/normal_5f870fa3c4251.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=subway%20surfers%20tokyo%202018
- https://cdn-cms.f-static.net/uploads/4366399/normal_5f87802fa79f7.pdf
- https://cdn-cms.f-static.net/uploads/4365619/normal_5f870fa3c4251.pdf
- https://cdn-cms.f-static.net/uploads/4366312/normal_5f8725a393ade.pdf
- https://cdn-cms.f-static.net/uploads/4367310/normal_5f87b35f092ce.pdf
- https://cdn-cms.f-static.net/uploads/4365606/normal_5f8775821968b.pdf
- https://cdn-cms.f-static.net/uploads/4368503/normal_5f878d04431a3.pdf
- https://cdn-cms.f-static.net/uploads/4366336/normal_5f8789517e4be.pdf
- https://cdn-cms.f-static.net/uploads/4365662/normal_5f87320241736.pdf
- https://cdn.shopify.com/s/files/1/0433/6405/7247/files/49810325830.pdf
- https://cdn.shopify.com/s/files/1/0484/4116/3926/files/tomefivavawevowixunede.pdf
- https://cdn.shopify.com/s/files/1/0431/1446/3394/files/bat_rolling_machine_for_sale.pdf
- https://cdn.shopify.com/s/files/1/0439/9464/4638/files/dajosixi.pdf
- https://site-1043887.mozfiles.com/files/1043887/kusobarutibajux.pdf
- https://site-1048442.mozfiles.com/files/1048442/toyota_chr_2020_user_manual.pdf
- https://uploads.strikinglycdn.com/files/46da9b5c-c1a8-4e69-a392-d0c42e622c93/37764183340.pdf
- https://uploads.strikinglycdn.com/files/01e16e6c-2682-4ef0-b41c-db071ca3a699/dezazukurisofusezefav.pdf
- https://uploads.strikinglycdn.com/files/2853358c-be6e-4bed-b39f-f1858c7d4639/kamojeruz.pdf
- https://cdn.shopify.com/s/files/1/0495/9155/0104/files/foxit_reader_merge_multiples.pdf
- https://cdn.shopify.com/s/files/1/0268/8253/9698/files/uniden_bc125at_manual.pdf
- https://cdn.shopify.com/s/files/1/0428/6201/8716/files/cali_y_el_dandee_-_yo_te_esperar_que_significa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1043887.mozfiles.com
- site-1048442.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report