SUSPICIOUS — 727805.pdf
SUSPICIOUS — 727805.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
42731a9a7acdea88bd71ed51b2b6381fdc62865153c5d68fb26493e4b2701a29 - SHA-1:
b1beb7c550fca83d0fb8fc234d2944e4626281e8 - MD5:
85d9a1c9a9c3b971f8f69cd233c40443 - ssdeep:
768:RgGzpD/pXqSHse0SXg4UWojWr1IJOfy2f43ttSD/cKoj2rL5pPlWfd5m9IwqJenm:iGF7pXq+a3/STcKrX5xlWfdYOXgav1 - TLSH:
T19D349EF31097EE4D7ACBAB039DB6102A444EC389A17797A044DCB63ED97C6AD6E20450 - Submitted as: 727805.pdf
- File type: pdf · Size: 52436 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=2006%20nissan%20pathfinder%20workshop%20manual, https://cdn.shopify.com/s/files/1/0481/8432/8344/files/the_breakfast_club_allison_character_analysis.pdf, https://cdn.shopify.com/s/files/1/0498/4989/3026/files/bmw_335i_owners_manual_2015.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=2006%20nissan%20pathfinder%20workshop%20manual
- https://cdn.shopify.com/s/files/1/0481/8432/8344/files/the_breakfast_club_allison_character_analysis.pdf
- https://cdn.shopify.com/s/files/1/0498/4989/3026/files/bmw_335i_owners_manual_2015.pdf
- https://cdn.shopify.com/s/files/1/0434/3254/2369/files/42789893325.pdf
- https://cdn.shopify.com/s/files/1/0433/3246/8890/files/ihss_protective_supervision.pdf
- https://uploads.strikinglycdn.com/files/372e84e2-b441-4d38-ae7f-d5d12ea91035/sudebuvuwikop.pdf
- https://uploads.strikinglycdn.com/files/0a4882a6-33b4-4583-8f33-6ddd661d79bd/58578718646.pdf
- https://uploads.strikinglycdn.com/files/fa3b141f-14e9-4aa9-9a11-e862e3f24173/xedakuxarad.pdf
- https://uploads.strikinglycdn.com/files/dd848be4-ca19-40fa-88c3-3f8fe4b3a5a3/sufowanifetirasir.pdf
- https://uploads.strikinglycdn.com/files/dd6bbbe9-fddd-400e-853e-adffef80b6a0/veluxoxo.pdf
- https://uploads.strikinglycdn.com/files/20608721-112d-4dcc-9455-4f82c0cc24b3/38662705721.pdf
- https://uploads.strikinglycdn.com/files/2702d873-9319-4f57-ba07-79fbfc55c4c5/92865800508.pdf
- https://uploads.strikinglycdn.com/files/d7f1c564-cd66-486a-88b7-46e85a020389/vovewafurediw.pdf
- https://uploads.strikinglycdn.com/files/dff1358b-273d-46b6-a831-ffe0ff82b4b5/zenamitobezogipaxupixow.pdf
- https://uploads.strikinglycdn.com/files/312ed98b-a222-46ef-ada0-0979d71e8d10/vudaxipuki.pdf
- https://cdn-cms.f-static.net/uploads/4366407/normal_5f875d10a86ff.pdf
- https://cdn-cms.f-static.net/uploads/4368238/normal_5f8870dd016c4.pdf
- https://cdn-cms.f-static.net/uploads/4365547/normal_5f880f128c39d.pdf
- https://cdn-cms.f-static.net/uploads/4367273/normal_5f87468ae619d.pdf
- https://cdn-cms.f-static.net/uploads/4366371/normal_5f878abeaecec.pdf
- https://uploads.strikinglycdn.com/files/0376c45a-5767-43bb-95c1-419c98d3bb9a/87445005923.pdf
- https://uploads.strikinglycdn.com/files/4802e0ac-247c-4c8a-afd7-3bee39f03b4e/pekumiriniwabi.pdf
- https://uploads.strikinglycdn.com/files/9f40f747-a1e0-48b3-b217-ad8873da3f8f/10330537659.pdf
- https://cdn.shopify.com/s/files/1/0439/0020/7272/files/adidas_watch_manual.pdf
- https://cdn.shopify.com/s/files/1/0433/3309/1496/files/the_town_mouse_and_the_country_mouse.pdf
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report