SUSPICIOUS — 881530.pdf
SUSPICIOUS — 881530.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
6b7f6a3c6b8b5e94957b5e31a2f667277675458e04f2d5aab6211e8533f8e924 - SHA-1:
c713386a1df63e0c1919ee7ea642c64c6a0d1857 - MD5:
2c78e08dcedd0acc54c40751e41cd56a - ssdeep:
768:agGzpDopwPvZdtuNlW/XPGnXirRUp9Z0mcaweEQFi9f:HGFcp3XirRUp9Z0mc3QFi9f - TLSH:
T1F5309DF3209BDC4C7A836B076DAB005A518AD6886137A36059CCB73CC8BC6BD7E61951 - Submitted as: 881530.pdf
- File type: pdf · Size: 38180 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=bentley%20pants%20press, https://cdn-cms.f-static.net/uploads/4366984/normal_5f897b2ac1ce3.pdf, https://cdn-cms.f-static.net/uploads/4368248/normal_5f881a747074d.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=bentley%20pants%20press
- https://cdn-cms.f-static.net/uploads/4366984/normal_5f897b2ac1ce3.pdf
- https://cdn-cms.f-static.net/uploads/4368248/normal_5f881a747074d.pdf
- https://cdn-cms.f-static.net/uploads/4365563/normal_5f87335db99b0.pdf
- https://cdn-cms.f-static.net/uploads/4366027/normal_5f874d57eb817.pdf
- https://cdn-cms.f-static.net/uploads/4367271/normal_5f87438892537.pdf
- https://cdn-cms.f-static.net/uploads/4368496/normal_5f88fb2cb0c4c.pdf
- https://cdn.shopify.com/s/files/1/0432/6457/3593/files/fractured_but_whole_trophies.pdf
- https://cdn.shopify.com/s/files/1/0438/1101/2770/files/5433584198.pdf
- https://cdn.shopify.com/s/files/1/0437/7578/7157/files/formato_carta_poder_word_gratis.pdf
- https://cdn.shopify.com/s/files/1/0268/7769/0035/files/tadafuzulon.pdf
- https://cdn.shopify.com/s/files/1/0268/7572/3971/files/35359064365.pdf
- https://cdn.shopify.com/s/files/1/0481/8049/4485/files/24833722593.pdf
- https://uploads.strikinglycdn.com/files/0fb1feee-c12e-4919-8f96-e5b1dc08bb7c/kumelemorovov.pdf
- https://uploads.strikinglycdn.com/files/92b66bd7-ecdf-44b4-bca6-05e2f8a49300/sizudolejewasuxezu.pdf
- https://uploads.strikinglycdn.com/files/f6f40a27-0766-4a0e-99f3-63bab4fccf38/wimikisajotawuwufof.pdf
- https://uploads.strikinglycdn.com/files/f1155ed7-918d-49e9-8d6c-c42e6789f0a2/vajulipavumi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report