SUSPICIOUS — a44574fec18a243.pdf
SUSPICIOUS — a44574fec18a243.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
64ac763c19b5142cf745398991d3e65b1e461bbcb52bfe57d55102b1f4bcea85 - SHA-1:
99bd72a81ab3f894d36e4072d7e09dc09aeabc4e - MD5:
b96f78ab294d4a0ce67f48f0055f98bd - ssdeep:
768:U/gGzpDteYjuQ5GIhQjWMhDeA7Yx6nUoq86VgyolJK3H2zMctPwhrzuR:pGFResekx6nUoq86VDolJO2QOPIrzuR - TLSH:
T113339DF75097DDDCBA8BAB0369BA10696189C74C2137D7A054C8376CD8BC6BCAE04D60 - Submitted as: a44574fec18a243.pdf
- File type: pdf · Size: 48516 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=dragon%20age%20inquisition%20hinterlands%20l, https://cdn-cms.f-static.net/uploads/4367013/normal_5f8737e2542fa.pdf, https://cdn-cms.f-static.net/uploads/4368788/normal_5f892a3ebd18c.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=dragon%20age%20inquisition%20hinterlands%20l
- https://cdn-cms.f-static.net/uploads/4367013/normal_5f8737e2542fa.pdf
- https://cdn-cms.f-static.net/uploads/4368788/normal_5f892a3ebd18c.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f8707c6d2fc6.pdf
- https://cdn-cms.f-static.net/uploads/4365655/normal_5f874e7d64c8a.pdf
- https://cdn-cms.f-static.net/uploads/4366360/normal_5f871636231c6.pdf
- https://uploads.strikinglycdn.com/files/4c379d4b-e984-4d58-b591-73a8beaa205c/30169577966.pdf
- https://uploads.strikinglycdn.com/files/8b6eb60c-d527-4d58-afa1-36c27a1c179e/zefufidokofojawa.pdf
- https://uploads.strikinglycdn.com/files/734ddb32-9adb-4b0d-9fb8-57209f864f6c/jevidataxi.pdf
- https://uploads.strikinglycdn.com/files/878e7f8f-e823-4208-a11b-bd92e327c147/botilobuwageb.pdf
- https://uploads.strikinglycdn.com/files/58d79d8e-84c4-45cb-b8b4-c473da153a86/92645350314.pdf
- https://uploads.strikinglycdn.com/files/4edd65ed-779a-4f36-828f-b74e5262a985/rumolovumujomezowizuli.pdf
- https://uploads.strikinglycdn.com/files/30f7ea84-3234-4d85-a537-fa355f63fe90/fufegopate.pdf
- https://uploads.strikinglycdn.com/files/e3787402-0836-4da0-8537-13990ba225e4/norugodibixo.pdf
- https://uploads.strikinglycdn.com/files/1994ed38-6333-4609-94d1-682aa1161b5d/88064519703.pdf
- https://uploads.strikinglycdn.com/files/6715e850-4289-4010-bee3-52f5711df977/66187981421.pdf
- https://uploads.strikinglycdn.com/files/3f955f07-d0ca-487c-abcf-24fcb7e8e143/lomamodisit.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report