SUSPICIOUS — f751495260.pdf
SUSPICIOUS — f751495260.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
41cdb495cfe64012e98d558b1d0659a8f4d5cbd2da20fa63340be6e2442329e4 - SHA-1:
feac0cc8591e7dda7e17442c168a2773420273e4 - MD5:
cf86285b45395ec8a75ab0df6d406400 - ssdeep:
768:EgGzpDOpj4cCa2OpqY/gQK+RhKqniybL4rzJ6UvN0n/kQhhttifSmawf79EaqK+d:xGFapz6F0n/koDi6mZ79xp+kkQd3d+j - TLSH:
T169327CF31097EC8E7A8F6F439EBB05A9648AC7896133D691058C772CD47C9ED2E00A51 - Submitted as: f751495260.pdf
- File type: pdf · Size: 43753 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=dnd%20combat%20actions, https://cdn.shopify.com/s/files/1/0479/5790/1468/files/refivezoridudogekakegabe.pdf, https://cdn.shopify.com/s/files/1/0433/0219/1269/files/87314274033.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=dnd%20combat%20actions
- https://cdn.shopify.com/s/files/1/0479/5790/1468/files/refivezoridudogekakegabe.pdf
- https://cdn.shopify.com/s/files/1/0433/0219/1269/files/87314274033.pdf
- https://cdn.shopify.com/s/files/1/0440/8895/0949/files/lupokisededuk.pdf
- https://cdn.shopify.com/s/files/1/0501/1187/3219/files/combine_files_in_one_page.pdf
- https://cdn.shopify.com/s/files/1/0440/9986/2680/files/natural_aromatase_inhibitors_bodybuilding.pdf
- https://cdn.shopify.com/s/files/1/0431/9117/3278/files/north_dakota_state_wrestling_tournament_2019_results.pdf
- https://cdn.shopify.com/s/files/1/0497/4228/2906/files/wixela.pdf
- https://cdn-cms.f-static.net/uploads/4375194/normal_5f895b9db9a0a.pdf
- https://cdn-cms.f-static.net/uploads/4368248/normal_5f87857618086.pdf
- https://cdn-cms.f-static.net/uploads/4367656/normal_5f88d24333108.pdf
- https://cdn-cms.f-static.net/uploads/4375907/normal_5f8bef1840cdf.pdf
- https://uploads.strikinglycdn.com/files/0aab0b2b-2f30-4ff7-a0e0-c9ced3633e32/43190388946.pdf
- https://uploads.strikinglycdn.com/files/7bf5fdad-93bf-4bb1-ba4e-91edc3cfd5a4/mepikilabenemutegutopitav.pdf
- https://uploads.strikinglycdn.com/files/e955092e-cf4e-4360-91bf-8fd48c50d7ba/70295467571.pdf
- https://uploads.strikinglycdn.com/files/83214a45-b92d-4b5a-bb32-e2e70e949919/16493481112.pdf
- https://uploads.strikinglycdn.com/files/5990c73e-49ee-43ac-9818-e414c4bd0f0a/pudavekanukax.pdf
- https://cdn.shopify.com/s/files/1/0503/0776/0311/files/akame_ga_kill_wallpaper_hd_android.pdf
- https://cdn.shopify.com/s/files/1/0502/1673/0799/files/solar_energy_conversion.pdf
- https://cdn.shopify.com/s/files/1/0500/5895/2872/files/lakewood_water_district_lawsuit.pdf
- https://cdn.shopify.com/s/files/1/0438/3768/5920/files/sony_cdx_gt320_wiring_diagram.pdf
- https://cdn.shopify.com/s/files/1/0431/2930/7293/files/what_is_a_po_number_when_ordering.pdf
- https://cdn-cms.f-static.net/uploads/4366376/normal_5f87ecd67a645.pdf
- https://cdn-cms.f-static.net/uploads/4370540/normal_5f8acefe86711.pdf
- https://cdn-cms.f-static.net/uploads/4381539/normal_5f8b748c80c80.pdf
Embedded domains
- gettraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- 3.fr
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report