SUSPICIOUS — 8b85cad4.pdf
SUSPICIOUS — 8b85cad4.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
633f87e6b789e9e38b0aa30140731b4946cce4db2865288046fae1833ca64b8b - SHA-1:
620ae94351c365774cc7882eae9d78ae9218d915 - MD5:
2a02361fb9d56476d2f82594504d3e40 - ssdeep:
768:OgGzpDNfvK+sRMoEjRQFYnWCNzDpiYwIOAxKRTompc+XzfqxgTPDuUMkZ2UiRfg:rGF5qrQzUYtO9TompFzfygTbudkZig - TLSH:
T16E338CF30093DD4DB6C7AB53ADA6252E944AD78C7132E6A044D8B72CD0BC3BD6E10961 - Submitted as: 8b85cad4.pdf
- File type: pdf · Size: 50106 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=tether%20bitcoin%20pdf, https://uploads.strikinglycdn.com/files/58667548-7af9-4a97-b725-640ca0ae3cdf/there_is_there_are_worksheet.pdf, https://uploads.strikinglycdn.com/files/d8990552-f76f-42a6-9dc0-26cd5cfa1e02/53126510320.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=tether%20bitcoin%20pdf
- https://uploads.strikinglycdn.com/files/58667548-7af9-4a97-b725-640ca0ae3cdf/there_is_there_are_worksheet.pdf
- https://uploads.strikinglycdn.com/files/d8990552-f76f-42a6-9dc0-26cd5cfa1e02/53126510320.pdf
- https://uploads.strikinglycdn.com/files/4c02bdc9-f0fa-464b-98ed-7ca2dfb1d604/19163973505.pdf
- https://uploads.strikinglycdn.com/files/bea7c389-e675-4d01-9be8-cf1f119b024a/dining_room_and_banquet_management_4.pdf
- https://cdn.shopify.com/s/files/1/0266/8327/7491/files/ios_design_guidelines_font_size.pdf
- https://cdn-cms.f-static.net/uploads/4381102/normal_5f8e3b0c394f0.pdf
- https://cdn-cms.f-static.net/uploads/4372681/normal_5f8d66e3b026f.pdf
- https://cdn-cms.f-static.net/uploads/4369313/normal_5f934cbb25017.pdf
- https://cdn-cms.f-static.net/uploads/4365541/normal_5f871ce6a8387.pdf
- https://jorimedazaget.weebly.com/uploads/1/3/0/7/130738946/fe3b313.pdf
- https://kubupukadumu.weebly.com/uploads/1/3/1/3/131382740/kugokikumuve-rinit.pdf
- https://rubazepenomul.weebly.com/uploads/1/3/4/3/134324915/tabijudas.pdf
- https://numomepezudoti.weebly.com/uploads/1/3/4/3/134320197/xevikar_renejuxo_zeruvomesopugoj_rafifuxojexod.pdf
- https://kiseridebajesa.weebly.com/uploads/1/3/1/4/131408791/zorup.pdf
- https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/fapolurefo-dubofibojarotof-kezefenobudijix.pdf
- https://lewonodi.weebly.com/uploads/1/3/4/3/134330754/zuduxeja-xapudufeto-liloboviri.pdf
- https://netaluzubik.weebly.com/uploads/1/3/0/8/130813777/6781803.pdf
- https://cdn.shopify.com/s/files/1/0438/9067/1771/files/pokemon_buddy_adventure_guide.pdf
- https://cdn.shopify.com/s/files/1/0485/0689/6539/files/learning_styles_questionnaire.pdf
- https://cdn.shopify.com/s/files/1/0498/9324/5086/files/rumakajavonatatusum.pdf
- https://cdn.shopify.com/s/files/1/0479/4531/8567/files/22691895573.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- jorimedazaget.weebly.com
- kubupukadumu.weebly.com
- rubazepenomul.weebly.com
- numomepezudoti.weebly.com
- kiseridebajesa.weebly.com
- babikovinemixe.weebly.com
- lewonodi.weebly.com
- netaluzubik.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report