SUSPICIOUS — 1953df354c.pdf
SUSPICIOUS — 1953df354c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
3cbbd85c4ada601aa6272069d5b8070c7283eb0617bce3007e55ab5273b38801 - SHA-1:
35c54d9d6052b729a7e7f0e1f4d5584069462e65 - MD5:
eb8832b9b938291915381edc679773f5 - ssdeep:
1536:qGFPeBiQsa0Nek/GSoQdN6SPePbIrhtrzN2AGXCNA8FB:TFPeNsaKgQdNSMrvr52BXCmy - TLSH:
T1B635ADF725ABED8C3A8BD743A9EB1509158DD38C223BDB500088762DC5BC2BD7E10921 - Submitted as: 1953df354c.pdf
- File type: pdf · Size: 59916 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=book%20review%20guide, https://cdn.shopify.com/s/files/1/0479/0114/7302/files/2130244366.pdf, https://cdn.shopify.com/s/files/1/0478/8446/8390/files/devolo_cockpit_app_fr_android.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=book%20review%20guide
- https://cdn.shopify.com/s/files/1/0479/0114/7302/files/2130244366.pdf
- https://cdn.shopify.com/s/files/1/0478/8446/8390/files/devolo_cockpit_app_fr_android.pdf
- https://cdn.shopify.com/s/files/1/0486/6424/8470/files/29454663390.pdf
- https://cdn.shopify.com/s/files/1/0431/4975/4519/files/pltw_poe_activity_2.1_6_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0430/9411/4455/files/tizigubiledusevofo.pdf
- https://uploads.strikinglycdn.com/files/d92ba037-ce93-4e26-bb33-5942ef03fe33/42578893178.pdf
- https://uploads.strikinglycdn.com/files/17bc150e-89ee-4934-babb-e27952da0c13/nurilesa.pdf
- https://uploads.strikinglycdn.com/files/8fa4bd25-6afa-4e2b-b7ac-9b84f50c21d7/jaxopubifed.pdf
- https://uploads.strikinglycdn.com/files/64a3c3f6-c6b6-47af-8b00-e19cb93829ed/1994_blockbuster_video_game_champion.pdf
- https://uploads.strikinglycdn.com/files/07954be9-e590-4c89-b13b-dd446bfe9936/99561880665.pdf
- https://s3.amazonaws.com/leguvefu/canciones_de_guitarra_clasica.pdf
- https://s3.amazonaws.com/tetazino/87269007473.pdf
- https://s3.amazonaws.com/zuxadol/what_is_bilingualism_and_multilingualism.pdf
- https://s3.amazonaws.com/xanebavifamopez/61219985108.pdf
- https://s3.amazonaws.com/leguvefu/78359234888.pdf
- https://uploads.strikinglycdn.com/files/e24463d0-beee-4223-89d0-b855b8c37268/xidosuxubisoxutekok.pdf
- https://uploads.strikinglycdn.com/files/69556f8d-40aa-4df0-81c9-20f3c77f2ed5/59217845915.pdf
- https://uploads.strikinglycdn.com/files/7f181ae0-dd0c-4b97-a3a5-d25d62c8a49f/72542555632.pdf
- https://uploads.strikinglycdn.com/files/d2238d9d-374e-48e8-be4d-2e9be806c58f/7745045605.pdf
- https://cdn.shopify.com/s/files/1/0479/9640/3871/files/95007053551.pdf
- https://cdn.shopify.com/s/files/1/0433/4672/2969/files/steelers_live_stream_free.pdf
- https://cdn.shopify.com/s/files/1/0498/1089/9099/files/different_ways_to_say_youre_welcome_in_email.pdf
- https://cdn.shopify.com/s/files/1/0485/8966/8512/files/tugebar.pdf
- https://cdn.shopify.com/s/files/1/0429/5367/0822/files/63069857347.pdf
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report