SUSPICIOUS — 3f86f13046bc.pdf
SUSPICIOUS — 3f86f13046bc.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
6102379133fb0a097a7582b350b647f8a063a0eac01402be091de20301570dbb - SHA-1:
a635d43358cf5db7c820b4704d8121327a8ae6b0 - MD5:
f5dd0c6e3b535edb03879dab64a3e5e6 - ssdeep:
3072:yFOpVzmoU48Sulrk5IrEJ1ckgaE+A3QrR8jjixLoqtuOLcfRh52o5RGS:iIJ+3jlrG1NHA3wiqt5LckoN - TLSH:
T1813FF1E310A7DC4CAB8B6F476E9B2588909DA71D2232C78454A4772DC6FC5BC6D10E32 - Submitted as: 3f86f13046bc.pdf
- File type: pdf · Size: 156131 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=how%20to%20find%20cephalon%20fragments%20on%20mars, https://site-1039426.mozfiles.com/files/1039426/dodojibiwalatezofexu.pdf, https://site-1043545.mozfiles.com/files/1043545/61394525660.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=how%20to%20find%20cephalon%20fragments%20on%20mars
- https://site-1039426.mozfiles.com/files/1039426/dodojibiwalatezofexu.pdf
- https://site-1043545.mozfiles.com/files/1043545/61394525660.pdf
- https://site-1040683.mozfiles.com/files/1040683/3687360482.pdf
- https://site-1044416.mozfiles.com/files/1044416/54424881231.pdf
- https://cdn.shopify.com/s/files/1/0434/1222/6206/files/zomalove.pdf
- https://cdn.shopify.com/s/files/1/0485/7872/4005/files/life_fitness_elliptical_x5.pdf
- https://site-1039271.mozfiles.com/files/1039271/77843627479.pdf
- https://site-1039251.mozfiles.com/files/1039251/venutudaberigube.pdf
- https://site-1039735.mozfiles.com/files/1039735/88016846057.pdf
- https://site-1036886.mozfiles.com/files/1036886/73718767296.pdf
- https://site-1039922.mozfiles.com/files/1039922/sokeruzokodam.pdf
- https://cdn.shopify.com/s/files/1/0484/0829/7624/files/gafogifukemalike.pdf
- https://cdn.shopify.com/s/files/1/0496/1543/7977/files/24421731712.pdf
- https://cdn.shopify.com/s/files/1/0482/5966/1985/files/amc_theatre_edwardsville_illinois.pdf
- https://cdn.shopify.com/s/files/1/0432/4828/7904/files/pleurx_drainage_kit_50-7510.pdf
- https://uploads.strikinglycdn.com/files/8855a1c4-3d8b-480b-8d2b-47068f6f3681/37328061140.pdf
- https://uploads.strikinglycdn.com/files/dc461c89-fc81-4f97-a811-3512535d893a/wanadivotujebavipuguviw.pdf
- https://uploads.strikinglycdn.com/files/9e1998a3-fef6-4a88-bf35-7964bd1f7c8a/89712696253.pdf
- https://uploads.strikinglycdn.com/files/f5d61075-62ff-41eb-ada2-84345af7ddd3/xukijimamipugabif.pdf
- https://uploads.strikinglycdn.com/files/7e5fc7db-2e71-45ad-90d7-b5869bdb2f97/60427704459.pdf
- https://uploads.strikinglycdn.com/files/b5e836af-81bb-49cd-b530-58b96173b399/giruweza.pdf
- https://uploads.strikinglycdn.com/files/38152613-835c-474a-befc-73c01a839b2d/tawibikixinit.pdf
- https://uploads.strikinglycdn.com/files/4c00eb8c-a613-4b56-a9d9-9781bb1e14de/wadizigozosupaboxi.pdf
- https://uploads.strikinglycdn.com/files/97bb9d0b-0369-475e-b064-1f8247cd4aff/32001736112.pdf
Embedded domains
- gettraff.ru
- site-1039426.mozfiles.com
- site-1043545.mozfiles.com
- site-1040683.mozfiles.com
- site-1044416.mozfiles.com
- cdn.shopify.com
- site-1039271.mozfiles.com
- site-1039251.mozfiles.com
- site-1039735.mozfiles.com
- site-1036886.mozfiles.com
- site-1039922.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report