SUSPICIOUS — 1811079.pdf
SUSPICIOUS — 1811079.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
3f648cbfd1f994f92c9ec002f739f14ed667e9a3f0b02f27d4da04bb079bf243 - SHA-1:
017ebf9d30adf227fb634f5b1c83ff20a85fdfbf - MD5:
e1e7d972ff1082561fe3c82e06dc0197 - ssdeep:
768:EgGzpDBpgHU6RzQ74Q/nGAQutSmOjMPsXuoos8mJy1UbukQZcL+E:xGFdpraUseo73y1aukQZcL+E - TLSH:
T14E318EF310A7ED4DBA8B6B236DAB149A5049D7882237D79005DC3B7CD1BC27D2E10865 - Submitted as: 1811079.pdf
- File type: pdf · Size: 42845 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=how%20to%20download%20cloned%20app, https://cdn-cms.f-static.net/uploads/4366376/normal_5f8875bcb0fc1.pdf, https://cdn-cms.f-static.net/uploads/4368763/normal_5f8b677216ed3.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=how%20to%20download%20cloned%20app
- https://cdn-cms.f-static.net/uploads/4366376/normal_5f8875bcb0fc1.pdf
- https://cdn-cms.f-static.net/uploads/4368763/normal_5f8b677216ed3.pdf
- https://cdn-cms.f-static.net/uploads/4368243/normal_5f8b65158b742.pdf
- https://cdn.shopify.com/s/files/1/0431/5706/1781/files/josisusepevitugi.pdf
- https://cdn.shopify.com/s/files/1/0438/7074/8827/files/sonic_adventure_ost_rar.pdf
- https://cdn.shopify.com/s/files/1/0433/2044/3045/files/lillebaby_carrier_complete_instructions.pdf
- https://cdn.shopify.com/s/files/1/0486/6015/2488/files/division_partial_quotients_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0496/6200/1301/files/self_employed_letter_for_schengen_visa.pdf
- https://uploads.strikinglycdn.com/files/f59d95c2-9a62-476d-b20a-b4f05ae92a40/14646656647.pdf
- https://uploads.strikinglycdn.com/files/ca35a1ce-d8b2-4804-b2d3-88c076177ecb/95751730338.pdf
- https://uploads.strikinglycdn.com/files/4a299e91-91e7-4329-8c08-d87653437d37/2358994304.pdf
- https://cdn-cms.f-static.net/uploads/4365598/normal_5f8b5ebc69cad.pdf
- https://cdn-cms.f-static.net/uploads/4382405/normal_5f8b7042aa09b.pdf
- https://cdn.shopify.com/s/files/1/0481/6093/1991/files/68012142785.pdf
- https://cdn.shopify.com/s/files/1/0500/1392/9630/files/drugs_to_avoid_in_g6pd.pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/3883418899.pdf
- https://cdn.shopify.com/s/files/1/0479/3833/8972/files/21846026593.pdf
- https://cdn.shopify.com/s/files/1/0440/7777/7061/files/bujuvilifagajezo.pdf
- https://dapujevubo.weebly.com/uploads/1/3/1/4/131438680/4abdc26250fc54.pdf
- https://mumixopid.weebly.com/uploads/1/3/1/8/131872042/322a80f51b.pdf
- https://jiwepurojal.weebly.com/uploads/1/3/0/7/130775762/lupemu_lumivexojadojex_bubufudisujexi_logejilobarug.pdf
- https://buxivadoga.weebly.com/uploads/1/3/0/7/130740323/mopexe-filebuk-pijonofozex-dusavuviwo.pdf
- https://bakuwosir.weebly.com/uploads/1/3/0/8/130874569/4546679.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- dapujevubo.weebly.com
- mumixopid.weebly.com
- jiwepurojal.weebly.com
- buxivadoga.weebly.com
- bakuwosir.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report