SUSPICIOUS — 3485073.pdf
SUSPICIOUS — 3485073.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
3a75d36c14039fb3eee8e0413fbedbeaed19da9e07c846a08ccd57ba928debfb - SHA-1:
d3669a41cbbae6111e5f12547efe042e49454e9e - MD5:
414fd19c1445ad03436cffbf774550dc - ssdeep:
768:YgGzpDRp1b5rqmVj3QDZsh3eSzmkMy01xQfcaU8L/SIvWNg8ovNM1c0Mr4s5ncLl:1GFNp6j13kbl+Ng80is4s5ycHCjumV5 - TLSH:
T15633AEF36097DD4C3AC3DB83A8AA2498A54AC68C61329250098CBB2CD1BC6BD7F10D51 - Submitted as: 3485073.pdf
- File type: pdf · Size: 48752 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=catan%20online%20gratis, https://uploads.strikinglycdn.com/files/44a68cf9-aac1-49fd-9193-4f3742606357/wapotuxonire.pdf, https://uploads.strikinglycdn.com/files/b04dd72d-e682-49e3-bb83-5c917476689e/65204524194.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=catan%20online%20gratis
- https://uploads.strikinglycdn.com/files/44a68cf9-aac1-49fd-9193-4f3742606357/wapotuxonire.pdf
- https://uploads.strikinglycdn.com/files/b04dd72d-e682-49e3-bb83-5c917476689e/65204524194.pdf
- https://uploads.strikinglycdn.com/files/ff6e0a96-ead6-46b4-8457-3d93da85a354/65762737944.pdf
- https://uploads.strikinglycdn.com/files/094a2ea8-5813-4f9e-bd58-5392690a70eb/vakisekakes.pdf
- https://cdn.shopify.com/s/files/1/0496/6721/1428/files/la_fitness_lake_success.pdf
- https://cdn.shopify.com/s/files/1/0431/7990/1096/files/jvc_dr-mv150_remote.pdf
- https://cdn.shopify.com/s/files/1/0430/4673/1930/files/kidkraft_uptown_kitchen_instructions.pdf
- https://cdn.shopify.com/s/files/1/0480/9572/3683/files/8900235358.pdf
- https://cdn.shopify.com/s/files/1/0481/6230/8247/files/98071190333.pdf
- https://cdn.shopify.com/s/files/1/0468/0715/4842/files/much_madness_is_divinest_sense_emily_dickinson.pdf
- https://cdn.shopify.com/s/files/1/0438/7376/3496/files/aba_model_rule_1.13.pdf
- https://cdn.shopify.com/s/files/1/0500/2743/0059/files/convert_to_to_excel_file.pdf
- https://cdn.shopify.com/s/files/1/0437/1261/0457/files/pimaxafazujimegig.pdf
- https://cdn.shopify.com/s/files/1/0483/4079/5555/files/vibimutivona.pdf
- https://cdn.shopify.com/s/files/1/0481/4045/1991/files/david_j_griffiths_introduction_to_electrodynamics_4th_edition_solution.pdf
- https://uploads.strikinglycdn.com/files/67c5ee32-db55-4505-8b4b-20953af452b5/wezefopanasobuzididepud.pdf
- https://uploads.strikinglycdn.com/files/c7986eb6-2b1e-487e-873f-9bb3285dd045/68746853836.pdf
- https://uploads.strikinglycdn.com/files/065c8136-c5fe-4f48-bebb-a10bd45f3e2b/zoguwijosemunogefakojofa.pdf
- https://cdn.shopify.com/s/files/1/0497/7603/3943/files/wosofazojeboxizudubemome.pdf
- https://cdn.shopify.com/s/files/1/0429/2132/8807/files/kpk_consumer_protection_act_2020.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report